AWS Glue Dev Endpoint Lifecycle Events (Create/Update/Delete) via CloudTrail

Flags Glue Create/Update/DeleteDevEndpoint API activity in CloudTrail that may indicate suspicious development endpoint management.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-10-03
Updated
2026-07-31

What it detects

This rule flags AWS Glue development endpoint activity by matching CloudTrail events for CreateDevEndpoint, UpdateDevEndpoint, and DeleteDevEndpoint with eventSource set to glue.amazonaws.com. Attackers may use these endpoints to manipulate or accelerate interactions with AWS Glue components during privilege escalation or other unauthorized activity. Detection relies on CloudTrail telemetry that records the initiating identity and the specific Glue API operations invoked.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.