forked from splunk/security_content
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathasl_aws_cloudtrail.yml
More file actions
35 lines (35 loc) · 904 Bytes
/
Copy pathasl_aws_cloudtrail.yml
File metadata and controls
35 lines (35 loc) · 904 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
name: ASL AWS CloudTrail
id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898
version: 6
creation_date: '2025-01-14'
modification_date: '2026-07-30'
author: Patrick Bareiss, Splunk
description: Represents AWS API dataset data collection from Amazon Security Lake.
mitre_components:
- Cloud Service Metadata
- Cloud Service Modification
- Cloud Storage Access
- Instance Creation
- Instance Deletion
- Instance Start
- Instance Stop
- Instance Modification
- Cloud Storage Creation
- Cloud Storage Deletion
- Cloud Service Enumeration
- Cloud Storage Enumeration
source: aws_asl
sourcetype: aws:asl
separator: api.operation
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 8.2.1
output_fields:
- dest
- user
- user_agent
- src
- vendor_account
- vendor_region
- vendor_product