Skip to content

Hide Navigation Hide TOC

New Network ACL Entry Added (e1f7febb-7b94-4234-b5c6-00fb8500f5dd)

Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.

Cluster A Galaxy A Cluster B Galaxy B Level
New Network ACL Entry Added (e1f7febb-7b94-4234-b5c6-00fb8500f5dd) Sigma-Rules Cloud Firewall - T1686.001 (ee474564-64be-4b83-a958-53f238f49b01) Attack Pattern 1
Cloud Firewall - T1686.001 (ee474564-64be-4b83-a958-53f238f49b01) Attack Pattern Disable or Modify System Firewall - T1686 (eec096b8-c207-43df-b6c1-11523861e452) Attack Pattern 2