Slide 25
Slide 25 text
© 2023 NTT DATA Corporation 25
5-1.カスタマイズ要素No.1
問題︓EventBridgeルールで検知した情報をSNSでメール通知する際に⽂⾯が⾒づらい
カスタマイズ内容︓テンプレート内でインプットトランスフォーマーを定義
{"version":"0","id":"XXXX","detail-type":"GuardDuty Finding","source":"aws.guardduty","account":"XXXXXX","time":"20XX-XX-
XXTXX:XX:XXZ","region":"ab-northeast-1","resources":[],"detail":{"schemaVersion":"2.0","accountId":"XXX","region":"ap-
northeast-1","partition":"aws","id":"XXXX","arn":"arn:aws:guardduty:ap-northeast-
1:XXXXXX:detector/XXXXXX/finding/XXXXXXXX","type":"Stealth:IAMUser/CloudTrailLoggingDisabled","resource":{"resourceT
ype":"AccessKey","accessKeyDetails":{"accessKeyId":"XXXXXXXX","principalId":"XXXXXXXX","userType":"IAMUser","userNa
me":"XXXXXXX"}},"service":{"serviceName":"guardduty","detectorId":"XXXXXX","action":{"actionType":"AWS_API_CALL","aw
sApiCallAction":{"api":"DeleteTrail","serviceName":"cloudtrail.amazonaws.com","callerType":"Remote
IP","remoteIpDetails":{"ipAddressV4":"X.X.X.X","organization":{"asn":"XXXX","asnOrg":"XXXX","isp":"XXX","org":"XXXX"},"cou
ntry":{"countryName":"Japan"},"city":{"cityName":"XXX"},"geoLocation":{"lat":XXX,"lon":XXX}},"affectedResources":{"AWS::Clo
udTrail::Trail":"arn:aws:cloudtrail:ap-northeast-
1:XXXXX:trail/XXX"}}},"resourceRole":"TARGET","additionalInfo":{},"evidence":null,"eventFirstSeen":"20XX-XX-
XXTXX:XX:XXZ","eventLastSeen":"20XX-XX-XXTXX:XX:XXZ","archived":false,"count":X},"severity":2,"createdAt":"20XX-XX-
XXTXX:XX:XX.XXXZ","updatedAt":"20XX-XX-XXTXX:XX:XX.XXXZ","title":"AWS CloudTrail trail arn:aws:cloudtrail:ap-
northeast-1:XXXXX:trail/XXXXXX was disabled.","description":"AWS CloudTrail trail arn:aws:cloudtrail:ap-northeast-
1:XXXXXXX:trail/XXXXX was disabled by XXXXX calling DeleteTrail under unusual circumstances. This can be attackers
attempt to cover their tracks by eliminating any trace of activity performed while they accessed your account."}}
--
If you wish to stop receiving notifications from this topic, please click or visit the link below to unsubscribe:
XXXXXX
Please do not reply directly to this email. If you have any questions or comments regarding this email, please contact us at
XXXX
"AWS XXXX has a severity 2 GuardDuty finding type Stealth:IAMUser/CloudTrailLoggingDisabled in the
ap-northeast-1 region."
"Finding Description:"
"AWS CloudTrail trail XXXXX was disabled by XXXXX calling DeleteTrail under unusual circumstances.
This can be attackers attempt to cover their tracks by eliminating any trace of activity performed while
they accessed your account.. "
"For more details open the GuardDuty console at XXXXXX
--
If you wish to stop receiving notifications from this topic, please click or visit the link below to
unsubscribe:
XXXX
Please do not reply directly to this email. If you have any questions or comments regarding this email,
please contact us at XXXXXX