bcgov / cloud-pathfinder

This is the technology and UX backend repo for the cloud pathfinder ZenHub task board
https://app.zenhub.com/workspaces/cloud-pathfinder-5e4dbb426c3c6af8dcbf06a7/board?repos=241742911
Creative Commons Zero v1.0 Universal
2 stars 8 forks source link

To use CSPM to monitor AWS Admin Console Login after Office Hours #3027

Closed bruce-wh-li closed 1 month ago

bruce-wh-li commented 3 months ago

Describe the Issue To add rule and policy to send notification to alert Admin Console Login event

Additional Context To detect Admin Console login in odd hours

Acceptance Criteria

bruce-wh-li commented 3 months ago

Office 365 Connectors within Teams will be retired soon. The Workflows app provides similar functionality with more scalability and security. Existing connectors will require a URL update to function after December 31st, 2024.

bruce-wh-li commented 1 month ago

CloudGuard CSPM is capable to detect admin login and can send alert via email notification. but, it lacks notification integration with other apps such as slack, team as of now.

CSPM->RuleSet->AWS BCGOV Best... cloudtrail should not have event.name like '%console%' or event.name like '%signintoken%'

Closed