Skip to content

Proposal: ASIM-aligned AWS GuardDuty parser and hunting queries #14768

Description

@OluOlus

I have developed and validated an ASIM-aligned parsing layer for AWS GuardDuty findings ingested through the existing Microsoft Sentinel AWS connector. The proposed contribution would extend the current AWS solution with:

  • an ASIM Network Session parser (ASimNetworkSessionAWSGuardDuty)
  • hunting queries for high-severity findings, EKS privilege escalation/credential access, and S3 public exposure
  • validation against the existing AWSGuardDuty table schema and the current AWS S3 connector

This proposal does not replace the existing AWS connector or the existing AWSGuardDuty - GuardDuty Alert analytic rule. It adds structured ASIM parsing and hunting content on top of the existing AWSGuardDuty table. I'd welcome guidance on whether this should be folded into the existing Amazon Web Services solution or submitted as standalone content.

Metadata

Metadata

Labels

ASIMHuntingHunting specialty review neededParserParser specialty review neededSolutionSolution specialty review neededenhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions