Skip to content

feat(detections): add 9 AWS + 9 O365 gap-fill rules - #2755

Merged
osmontero merged 2 commits into
v11from
feat/aws-o365-detection-gap-fill
Sep 25, 2026
Merged

osmontero merged 2 commits into
v11from
feat/aws-o365-detection-gap-fill

Conversation

@osmontero

Copy link
Copy Markdown
Member

Coverage gap-fill: 9 AWS + 9 O365 detections

Follows up the gap analysis vs Wazuh / SigmaHQ / Elastic Security / Microsoft Sentinel / MITRE ATT&CK Cloud. Adds the highest-severity missing detections as new rules only — no filter changes.

AWS (KryonX v1.1.x schema — log.awsRecordType + log.eventName + actionResult)

Defense-evasion / impact / credential tier:

Rule Trigger Gap
aws_cloudtrail_trail_created CreateTrail second/shadow trail (T1685)
aws_guardduty_detector_updated UpdateDetector enable=false disable w/o delete (T1685)
aws_guardduty_finding_filter PutFilters suppress findings (T1685)
aws_securityhub_disabled DisableSecurityHub turn off SecHub (T1685)
aws_s3_bucket_logging_disabled PutBucketLogging no target kill S3 access log (T1562.008)
aws_rds_deletion_protection_or_password_changed ModifyDBInstance disable del-protection / change master pw (T1485)
aws_kms_key_disabled_or_deletion DisableKey/ScheduleKeyDeletion render data unreadable (T1486)
aws_account_closed CloseAccount account endgame (T1485)
aws_sts_assume_role_with_web_identity AssumeRoleWithWebIdentity K8s/CI OIDC token abuse (T1550)

Each ships a positive CloudTrail fixture in aws_raw.json; contract count bumped 73→82; filter-contracts/aws.json manifest updated.

O365 (my v1.2.3 schema — action + actionResult + log.Parameters)

Rule Operation Gap
o365_mailbox_mass_access MailItemsAccessed bulk mailbox scrape (T1114)
o365_mailbox_login_nonowner MailboxLogin non-owner mailbox access (T1078)
o365_cas_autoforward Set-CASMailbox forwarding CAS-level exfil (T1114)
o365_mailbox_folder_permission Add-MailboxFolderPermission folder delegation (T1098)
o365_conditional_access_changed Disable/UpdateConditionalAccessPolicy CA weakened (T1562)
o365_dlp_policy_removed Remove-DlpPolicy DLP removed (T1562)
o365_mailbox_audit_bypass Set-MailboxAuditBypassAssociation audit bypass (T1562)
o365_file_malware_detected FileMalwareDetected malware staged (T1204)
o365_security_alert_added AlertAdded Defender alert surfaced

All validated through the plugins/alerts offline contract harness (TestAWSRawContracts + TestFilterAndRuleContracts pass).

Coordination

  • Depends on / overlaps @kryonsx #2660 and #2661 (both touch filters/aws/aws.yml, aws_contract_test.go, aws_raw.json, filter-contracts/aws.json, and the same O365 area). This PR should be rebased onto whichever of those merges first — the AWS rules assume his v1.1.x filter schema is final.
  • I have not touched the filter in this PR (the collector self-noise drop from my earlier work stays out per decision — it's per-deployment tuning, not vendor code).
  • Draft until KryonX reviews the schema assumption + the new fixtures.

@github-actions

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./utmstack-collector:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/gcp:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.88.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/events:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/inputs:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/stats:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/rule-flood-guard:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/o365:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/modules-config:
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.6
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.6
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.88.1
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.1
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/config:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/soc-ai:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/sophos:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/azure:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/crowdstrike:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/bitdefender:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./plugins/geolocation:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent-manager:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./agent:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

  📁 ./as400/updater:
     - github.com/threatwinds/go-sdk: v1.1.34 → v1.1.36

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

✅ AI review — Approved

No issues detected in this diff.

✅ architecture (silas-1.7-pro) — clean

Summary: No architectural deviations detected; diff only adds alert rule test fixtures and contract expectations.

No findings.

✅ bugs (silas-1.7-pro) — clean

Summary: No concrete bugs introduced by the diff; test count, fixture additions, and rule list additions are consistent.

No findings.

✅ security (silas-1.7-pro) — clean

Summary: No vulnerabilities or customer-facing information disclosures introduced by test fixture and contract updates.

No findings.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

Closes the highest-severity coverage gaps identified against Wazuh,
SigmaHQ, Elastic Security, Microsoft Sentinel, and MITRE ATT&CK Cloud.

AWS (defense-evasion / impact / credential tier, KryonX v1.1.x schema):
- aws_cloudtrail_trail_created          CreateTrail
- aws_guardduty_detector_updated        UpdateDetector (enable=false)
- aws_guardduty_finding_filter          PutFilters
- aws_securityhub_disabled              DisableSecurityHub
- aws_s3_bucket_logging_disabled        PutBucketLogging (no target)
- aws_rds_deletion_protection_or_password_changed  ModifyDBInstance
- aws_kms_key_disabled_or_deletion      DisableKey / ScheduleKeyDeletion
- aws_account_closed                    CloseAccount
- aws_sts_assume_role_with_web_identity AssumeRoleWithWebIdentity

Each ships a positive CloudTrail fixture in aws_raw.json; the contract
count is bumped 73 -> 82 and the filter-contract manifest updated.

O365 (my v1.2.3 schema, action + actionResult + log.Parameters):
- o365_mailbox_mass_access     MailItemsAccessed
- o365_mailbox_login_nonowner  MailboxLogin
- o365_cas_autoforward         Set-CASMailbox (forwarding)
- o365_mailbox_folder_permission Add-MailboxFolderPermission
- o365_conditional_access_changed  Disable/UpdateConditionalAccessPolicy
- o365_dlp_policy_removed      Remove-DlpPolicy
- o365_mailbox_audit_bypass    Set-MailboxAuditBypassAssociation
- o365_file_malware_detected   FileMalwareDetected
- o365_security_alert_added    AlertAdded

All validated via the plugins/alerts offline contract harness
(TestAWSRawContracts + TestFilterAndRuleContracts). No filter changes —
every O365 operation passes the existing v1.2.3 drop-list.
@osmontero
osmontero force-pushed the feat/aws-o365-detection-gap-fill branch from 4b97f4c to 90cb078 Compare September 25, 2026 18:11

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

FileMalwareDetected (RecordType 6) and AlertAdded (RecordType 78) are
system-generated detections that carry no ResultStatus in production.
KryonX's v1.4.1 filter (merged #2661) therefore never resolves
actionResult=success for them, which would silently dead the rules.
The event's presence is the signal, so match on action alone.

Verified against the real filter + production data shapes: all 9 O365
gap rules now fire (MailboxLogin RT2/Succeeded, Set-CASMailbox +
Add-MailboxFolderPermission + Remove-DlpPolicy + Set-MailboxAuditBypass
RT1/True, Disable/UpdateConditionalAccessPolicy RT8/Success,
MailItemsAccessed RT50/Succeeded, FileMalwareDetected RT6 + AlertAdded
RT78 no-ResultStatus).

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes requested — Go dependencies check failed (see above).

@osmontero
osmontero marked this pull request as ready for review September 25, 2026 22:31
@osmontero
osmontero requested a review from a team September 25, 2026 22:31
@osmontero
osmontero merged commit dda9d45 into v11 Sep 25, 2026
5 of 7 checks passed
@osmontero
osmontero deleted the feat/aws-o365-detection-gap-fill branch September 25, 2026 22:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant