Forum Discussion

viralshah007's avatar
viralshah007
Copper Contributor
Sep 10, 2020

AWS CloudTrail events Query

1 ) On Threat Intelligent Technic AWS Cloud trail and also looking for Relevant  Techniques (TXXX)  , find Query to looks in to cloud trail any IOC form TI.  Provide the Mitre Techniques name and Query . 

 

2 ) Sign in logs Form Email IOC , Looking for  MITRE technique name and Query to Run on sentinel.  

Resources