AWS ElastiCache Security Group Modified or Deleted (CloudTrail)

Flags CloudTrail activity indicating an ElastiCache security group was modified or deleted.

FreeUnreviewedSigmalowv1
title: AWS ElastiCache Security Group Modified or Deleted (CloudTrail)
id: ec9f0a7f-cca0-488d-b001-7ec835ce28b1
status: test
description: This rule identifies CloudTrail events where an ElastiCache security group is modified via ingress or egress authorization/revocation, or deleted. Attackers may change cache network access controls to alter which clients can reach ElastiCache or to disrupt service. It relies on AWS CloudTrail records with event source elasticache.amazonaws.com and specific event names for security group ingress/egress changes and deletion.
references:
  - https://github.com/elastic/detection-rules/blob/7d5efd68603f42be5e125b5a6a503b2ef3ac0f4e/rules/integrations/aws/impact_elasticache_security_group_modified_or_deleted.toml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_elasticache_security_group_modified_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-07-24
modified: 2022-10-09
tags:
  - attack.impact
  - attack.t1531
logsource:
  product: aws
  service: cloudtrail
detection:
  selection:
    eventSource: elasticache.amazonaws.com
    eventName:
      - DeleteCacheSecurityGroup
      - AuthorizeCacheSecurityGroupIngress
      - RevokeCacheSecurityGroupIngress
      - AuthorizeCacheSecurityGroupEgress
      - RevokeCacheSecurityGroupEgress
  condition: selection
falsepositives:
  - A ElastiCache security group deletion may be done by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security Group deletions from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
  - id: 7c797da2-9cf2-4523-ba64-33b06339f0cc
    type: derived

What it detects

This rule identifies CloudTrail events where an ElastiCache security group is modified via ingress or egress authorization/revocation, or deleted. Attackers may change cache network access controls to alter which clients can reach ElastiCache or to disrupt service. It relies on AWS CloudTrail records with event source elasticache.amazonaws.com and specific event names for security group ingress/egress changes and deletion.

Known false positives

  • A ElastiCache security group deletion may be done by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security Group deletions from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.