Skip to content

saakov-aws-1#6042

Open
saakovv wants to merge 3 commits into
SigmaHQ:masterfrom
saakovv:saakov-aws-1
Open

saakov-aws-1#6042
saakovv wants to merge 3 commits into
SigmaHQ:masterfrom
saakovv:saakov-aws-1

Conversation

@saakovv

@saakovv saakovv commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

Summary of the Pull Reques

Adds new AWS CloudTrail detection rules covering attack surfaces not yet represented in the Sigma ruleset. Rules were identified by gap analysis comparing the existing rules/cloud/aws/cloudtrail/ corpus against a production AWS environment monitoring

Coverage includes:

AWS Backup destruction - ransomware precursor pattern (vault/recovery point deletion)

Changelog:
new: AWS Backup Vault or Recovery Point Deleted

@github-actions

github-actions Bot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

Welcome 👋

It looks like this is your first pull request on the Sigma rules repository!

Please make sure to read the SigmaHQ conventions to make sure your contribution is adhering to best practices and has all the necessary elements in place for a successful approval.

Thanks again, and welcome to the Sigma community! 😃

@github-actions github-actions Bot added Rules Review Needed The PR requires review labels Jun 2, 2026
@saakovv

saakovv commented Jun 2, 2026

Copy link
Copy Markdown
Contributor Author
Screenshot 2026-06-02 at 4 00 21 PM Screenshot 2026-06-02 at 4 04 37 PM Screenshot 2026-06-02 at 4 13 00 PM

@saakovv

saakovv commented Jun 2, 2026

Copy link
Copy Markdown
Contributor Author

@swachchhanda000

Hi, based on all my PR based on #5998
Yes, I previously used Cloude to do everything quickly and centrally based on my alerts, now I will add each alert separately so that you can make sure that they are working))

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant