I have developed and validated an ASIM-aligned parsing layer for AWS GuardDuty findings ingested through the existing Microsoft Sentinel AWS connector. The proposed contribution would extend the current AWS solution with:
- an ASIM Network Session parser (
ASimNetworkSessionAWSGuardDuty)
- hunting queries for high-severity findings, EKS privilege escalation/credential access, and S3 public exposure
- validation against the existing
AWSGuardDuty table schema and the current AWS S3 connector
This proposal does not replace the existing AWS connector or the existing AWSGuardDuty - GuardDuty Alert analytic rule. It adds structured ASIM parsing and hunting content on top of the existing AWSGuardDuty table. I'd welcome guidance on whether this should be folded into the existing Amazon Web Services solution or submitted as standalone content.
I have developed and validated an ASIM-aligned parsing layer for AWS GuardDuty findings ingested through the existing Microsoft Sentinel AWS connector. The proposed contribution would extend the current AWS solution with:
ASimNetworkSessionAWSGuardDuty)AWSGuardDutytable schema and the current AWS S3 connectorThis proposal does not replace the existing AWS connector or the existing
AWSGuardDuty - GuardDuty Alertanalytic rule. It adds structured ASIM parsing and hunting content on top of the existingAWSGuardDutytable. I'd welcome guidance on whether this should be folded into the existing Amazon Web Services solution or submitted as standalone content.