M ManySignal
Detection Pack Amazon Web Services

AWS Detection Pack

68 production-ready detection rules covering CloudTrail, GuardDuty, S3, IAM, EC2, and more. Full MITRE ATT&CK mapping. One-click activation — start detecting AWS threats in minutes, not weeks.

Pack summary

Total rules
68
Critical rules
18
Data sources
8
ATT&CK techniques
24

What's included

AWS threat categories covered

Identity & Access

22 rules

IAM key creation, role assumption anomalies, privilege escalation paths

Data Exfiltration

12 rules

S3 mass download, cross-account copy, public exposure detection

Defense Evasion

10 rules

CloudTrail disablement, log deletion, GuardDuty and Config deactivation

Compute & Execution

11 rules

EC2 user data abuse, Lambda anomalies, ECS task launches

GuardDuty Findings

8 rules

Enriched ingestion of all GuardDuty finding types with entity context

Secrets & Credentials

5 rules

Secrets Manager access, SSM Parameter Store sensitive value reads

Sample detection rules

Showing 20 of 68 rules. All rules visible after connecting your AWS account.

Rule name Severity ATT&CK

CloudTrail StopLogging / DeleteTrail

Adversary disables AWS audit logging to cover tracks.

Critical T1562.008

IAM Access Key Created Outside Provisioning Window

New IAM access key created by unexpected principal or at unusual time.

Critical T1098.001

AWS Console Sign-In Without MFA

Root or IAM user authenticates to console without multi-factor authentication.

High T1078.004

AWS Root Account Login

Root account login detected — should be zero in a well-governed environment.

Critical T1078.004

GuardDuty Detector Disabled

GuardDuty threat detection disabled for an account or region.

Critical T1562.001

Public S3 Bucket Access Control List

S3 bucket ACL or policy modified to allow public access.

High T1530

Mass S3 Object Download — Data Exfiltration Pattern

IAM principal downloads anomalously high volume of S3 objects.

High T1530

Cross-Account S3 Copy — Data Exfiltration

Data copied to S3 bucket in external AWS account.

Critical T1537

New IAM User Created

IAM user created outside of approved provisioning pipeline.

Medium T1136.003

Admin Policy Attached to IAM User

AdministratorAccess policy attached to IAM user directly.

High T1098.003

EC2 Instance Metadata Service v1 Access

IMDSv1 accessed — allows credential theft from EC2 metadata without token.

Medium T1552.005

Security Group Modified to Allow Unrestricted Access

Inbound rule added permitting 0.0.0.0/0 access on sensitive ports.

High T1562.007

GuardDuty High-Severity Finding

GuardDuty reports a high-confidence threat finding (severity 7.0+).

Critical Various

Impossible Travel — AWS Console Sign-In

Two console sign-ins from geographically impossible locations for same user.

High T1078.004

Lambda Function Created in Unusual Region

Lambda function created in a region where none exist for this account.

Medium T1059.009

KMS Key Deleted or Scheduled for Deletion

KMS key deletion disables decryption of protected data.

Critical T1485

CloudTrail S3 Bucket Log Deletion

Objects deleted from CloudTrail log delivery S3 bucket.

Critical T1070.004

IAM Policy Modified to Allow Privilege Escalation Path

IAM policy change introduces a known privilege escalation permission combination.

High T1548

EC2 Instance Launched with Privileged User Data

EC2 user data script contains commands that establish backdoors or download payloads.

High T1059.009

AWS Secrets Manager Secret Accessed by Unusual Principal

Secret Manager GetSecretValue called by a principal outside the expected service scope.

High T1552.001

Prerequisites

What you need before activating

  • AWS CloudTrail enabled in all regions with multi-region trail and S3 log delivery
  • AWS GuardDuty enabled — free-tier coverage for the first 30 days in new accounts
  • ManySignal AWS connector configured with the cross-account IAM role (CloudFormation template provided)
  • S3 bucket for CloudTrail logs with SQS or EventBridge notification for real-time delivery

AWS Detection Pack: frequently asked questions

What AWS services does this detection pack cover?

The AWS detection pack covers CloudTrail (management and data events), GuardDuty findings, S3 Access Logs, VPC Flow Logs, AWS Config change events, Security Hub findings, Secrets Manager access logs, and CloudWatch events. Complete coverage requires CloudTrail enabled in all regions with S3 delivery.

How long does it take to activate the AWS detection pack?

One-click activation deploys all 68 rules immediately. Active detection begins as soon as CloudTrail and GuardDuty data is flowing into ManySignal — typically within minutes of connector setup.

Can I customise the detection rules?

Yes. Every rule in the AWS detection pack is built on ManySignal's Detection-as-Code platform. You can modify thresholds, add exceptions for known-good patterns, or fork rules to create custom variants. Changes are version-controlled and testable against historical data.

Does this pack cover GuardDuty Runtime Monitoring for containers?

Yes. GuardDuty Runtime Monitoring findings for EKS, ECS, and Lambda are ingested and covered by the pack's GuardDuty rules. Container-specific findings (privileged process in container, file access in container) map to additional detection rules.

How does the pack handle multi-account AWS organisations?

The AWS detection pack works with ManySignal's multi-account connector. GuardDuty and Security Hub findings from all member accounts flow to the delegated administrator and are ingested centrally. Account metadata is preserved in every alert for proper scoping.

68 AWS detections, deployed in minutes

Connect your AWS account and activate the detection pack. Your first verdicts appear in the dashboard within minutes — no rule tuning required.