Skip to content

Hide Navigation Hide TOC

New Network ACL Entry Added (e1f7febb-7b94-4234-b5c6-00fb8500f5dd)

Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.

Cluster A Galaxy A Cluster B Galaxy B Level
New Network ACL Entry Added (e1f7febb-7b94-4234-b5c6-00fb8500f5dd) Sigma-Rules Disable or Modify Cloud Firewall - T1562.007 (77532a55-c283-4cd2-bc5d-2d0b65e9d88c) Attack Pattern 1
Disable or Modify Cloud Firewall - T1562.007 (77532a55-c283-4cd2-bc5d-2d0b65e9d88c) Attack Pattern Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern 2