AWS Detection Pack
68 production-ready detection rules covering CloudTrail, GuardDuty, S3, IAM, EC2, and more. Full MITRE ATT&CK mapping. One-click activation — start detecting AWS threats in minutes, not weeks.
Pack summary
- Total rules
- 68
- Critical rules
- 18
- Data sources
- 8
- ATT&CK techniques
- 24
What's included
AWS threat categories covered
Identity & Access
22 rulesIAM key creation, role assumption anomalies, privilege escalation paths
Data Exfiltration
12 rulesS3 mass download, cross-account copy, public exposure detection
Defense Evasion
10 rulesCloudTrail disablement, log deletion, GuardDuty and Config deactivation
Compute & Execution
11 rulesEC2 user data abuse, Lambda anomalies, ECS task launches
GuardDuty Findings
8 rulesEnriched ingestion of all GuardDuty finding types with entity context
Secrets & Credentials
5 rulesSecrets Manager access, SSM Parameter Store sensitive value reads
Sample detection rules
Showing 20 of 68 rules. All rules visible after connecting your AWS account.
| Rule name | Severity | ATT&CK | Source |
|---|---|---|---|
| CloudTrail StopLogging / DeleteTrail Adversary disables AWS audit logging to cover tracks. | Critical | T1562.008 | CloudTrail |
| IAM Access Key Created Outside Provisioning Window New IAM access key created by unexpected principal or at unusual time. | Critical | T1098.001 | CloudTrail |
| AWS Console Sign-In Without MFA Root or IAM user authenticates to console without multi-factor authentication. | High | T1078.004 | CloudTrail |
| AWS Root Account Login Root account login detected — should be zero in a well-governed environment. | Critical | T1078.004 | CloudTrail |
| GuardDuty Detector Disabled GuardDuty threat detection disabled for an account or region. | Critical | T1562.001 | CloudTrail |
| Public S3 Bucket Access Control List S3 bucket ACL or policy modified to allow public access. | High | T1530 | CloudTrail |
| Mass S3 Object Download — Data Exfiltration Pattern IAM principal downloads anomalously high volume of S3 objects. | High | T1530 | CloudTrail |
| Cross-Account S3 Copy — Data Exfiltration Data copied to S3 bucket in external AWS account. | Critical | T1537 | CloudTrail |
| New IAM User Created IAM user created outside of approved provisioning pipeline. | Medium | T1136.003 | CloudTrail |
| Admin Policy Attached to IAM User AdministratorAccess policy attached to IAM user directly. | High | T1098.003 | CloudTrail |
| EC2 Instance Metadata Service v1 Access IMDSv1 accessed — allows credential theft from EC2 metadata without token. | Medium | T1552.005 | CloudTrail |
| Security Group Modified to Allow Unrestricted Access Inbound rule added permitting 0.0.0.0/0 access on sensitive ports. | High | T1562.007 | CloudTrail |
| GuardDuty High-Severity Finding GuardDuty reports a high-confidence threat finding (severity 7.0+). | Critical | Various | GuardDuty |
| Impossible Travel — AWS Console Sign-In Two console sign-ins from geographically impossible locations for same user. | High | T1078.004 | CloudTrail |
| Lambda Function Created in Unusual Region Lambda function created in a region where none exist for this account. | Medium | T1059.009 | CloudTrail |
| KMS Key Deleted or Scheduled for Deletion KMS key deletion disables decryption of protected data. | Critical | T1485 | CloudTrail |
| CloudTrail S3 Bucket Log Deletion Objects deleted from CloudTrail log delivery S3 bucket. | Critical | T1070.004 | CloudTrail |
| IAM Policy Modified to Allow Privilege Escalation Path IAM policy change introduces a known privilege escalation permission combination. | High | T1548 | CloudTrail |
| EC2 Instance Launched with Privileged User Data EC2 user data script contains commands that establish backdoors or download payloads. | High | T1059.009 | CloudTrail |
| AWS Secrets Manager Secret Accessed by Unusual Principal Secret Manager GetSecretValue called by a principal outside the expected service scope. | High | T1552.001 | CloudTrail |
Prerequisites
What you need before activating
- AWS CloudTrail enabled in all regions with multi-region trail and S3 log delivery
- AWS GuardDuty enabled — free-tier coverage for the first 30 days in new accounts
- ManySignal AWS connector configured with the cross-account IAM role (CloudFormation template provided)
- S3 bucket for CloudTrail logs with SQS or EventBridge notification for real-time delivery
AWS Detection Pack: frequently asked questions
What AWS services does this detection pack cover?
The AWS detection pack covers CloudTrail (management and data events), GuardDuty findings, S3 Access Logs, VPC Flow Logs, AWS Config change events, Security Hub findings, Secrets Manager access logs, and CloudWatch events. Complete coverage requires CloudTrail enabled in all regions with S3 delivery.
How long does it take to activate the AWS detection pack?
One-click activation deploys all 68 rules immediately. Active detection begins as soon as CloudTrail and GuardDuty data is flowing into ManySignal — typically within minutes of connector setup.
Can I customise the detection rules?
Yes. Every rule in the AWS detection pack is built on ManySignal's Detection-as-Code platform. You can modify thresholds, add exceptions for known-good patterns, or fork rules to create custom variants. Changes are version-controlled and testable against historical data.
Does this pack cover GuardDuty Runtime Monitoring for containers?
Yes. GuardDuty Runtime Monitoring findings for EKS, ECS, and Lambda are ingested and covered by the pack's GuardDuty rules. Container-specific findings (privileged process in container, file access in container) map to additional detection rules.
How does the pack handle multi-account AWS organisations?
The AWS detection pack works with ManySignal's multi-account connector. GuardDuty and Security Hub findings from all member accounts flow to the delegated administrator and are ingested centrally. Account metadata is preserved in every alert for proper scoping.
68 AWS detections, deployed in minutes
Connect your AWS account and activate the detection pack. Your first verdicts appear in the dashboard within minutes — no rule tuning required.