feat(detections): add 9 AWS + 9 O365 gap-fill rules - #2755
Merged
Merged
Conversation
❌ Go dependencies check failedThere are outdated Go dependencies, or modules that could not be inspected. Script output |
✅ AI review — ApprovedNo issues detected in this diff. ✅
|
Closes the highest-severity coverage gaps identified against Wazuh, SigmaHQ, Elastic Security, Microsoft Sentinel, and MITRE ATT&CK Cloud. AWS (defense-evasion / impact / credential tier, KryonX v1.1.x schema): - aws_cloudtrail_trail_created CreateTrail - aws_guardduty_detector_updated UpdateDetector (enable=false) - aws_guardduty_finding_filter PutFilters - aws_securityhub_disabled DisableSecurityHub - aws_s3_bucket_logging_disabled PutBucketLogging (no target) - aws_rds_deletion_protection_or_password_changed ModifyDBInstance - aws_kms_key_disabled_or_deletion DisableKey / ScheduleKeyDeletion - aws_account_closed CloseAccount - aws_sts_assume_role_with_web_identity AssumeRoleWithWebIdentity Each ships a positive CloudTrail fixture in aws_raw.json; the contract count is bumped 73 -> 82 and the filter-contract manifest updated. O365 (my v1.2.3 schema, action + actionResult + log.Parameters): - o365_mailbox_mass_access MailItemsAccessed - o365_mailbox_login_nonowner MailboxLogin - o365_cas_autoforward Set-CASMailbox (forwarding) - o365_mailbox_folder_permission Add-MailboxFolderPermission - o365_conditional_access_changed Disable/UpdateConditionalAccessPolicy - o365_dlp_policy_removed Remove-DlpPolicy - o365_mailbox_audit_bypass Set-MailboxAuditBypassAssociation - o365_file_malware_detected FileMalwareDetected - o365_security_alert_added AlertAdded All validated via the plugins/alerts offline contract harness (TestAWSRawContracts + TestFilterAndRuleContracts). No filter changes — every O365 operation passes the existing v1.2.3 drop-list.
osmontero
force-pushed
the
feat/aws-o365-detection-gap-fill
branch
from
September 25, 2026 18:11
4b97f4c to
90cb078
Compare
FileMalwareDetected (RecordType 6) and AlertAdded (RecordType 78) are system-generated detections that carry no ResultStatus in production. KryonX's v1.4.1 filter (merged #2661) therefore never resolves actionResult=success for them, which would silently dead the rules. The event's presence is the signal, so match on action alone. Verified against the real filter + production data shapes: all 9 O365 gap rules now fire (MailboxLogin RT2/Succeeded, Set-CASMailbox + Add-MailboxFolderPermission + Remove-DlpPolicy + Set-MailboxAuditBypass RT1/True, Disable/UpdateConditionalAccessPolicy RT8/Success, MailItemsAccessed RT50/Succeeded, FileMalwareDetected RT6 + AlertAdded RT78 no-ResultStatus).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Coverage gap-fill: 9 AWS + 9 O365 detections
Follows up the gap analysis vs Wazuh / SigmaHQ / Elastic Security / Microsoft Sentinel / MITRE ATT&CK Cloud. Adds the highest-severity missing detections as new rules only — no filter changes.
AWS (KryonX v1.1.x schema —
log.awsRecordType+log.eventName+actionResult)Defense-evasion / impact / credential tier:
aws_cloudtrail_trail_createdCreateTrailaws_guardduty_detector_updatedUpdateDetectorenable=falseaws_guardduty_finding_filterPutFiltersaws_securityhub_disabledDisableSecurityHubaws_s3_bucket_logging_disabledPutBucketLoggingno targetaws_rds_deletion_protection_or_password_changedModifyDBInstanceaws_kms_key_disabled_or_deletionDisableKey/ScheduleKeyDeletionaws_account_closedCloseAccountaws_sts_assume_role_with_web_identityAssumeRoleWithWebIdentityEach ships a positive CloudTrail fixture in
aws_raw.json; contract count bumped 73→82;filter-contracts/aws.jsonmanifest updated.O365 (my v1.2.3 schema —
action+actionResult+log.Parameters)o365_mailbox_mass_accessMailItemsAccessedo365_mailbox_login_nonownerMailboxLogino365_cas_autoforwardSet-CASMailboxforwardingo365_mailbox_folder_permissionAdd-MailboxFolderPermissiono365_conditional_access_changedDisable/UpdateConditionalAccessPolicyo365_dlp_policy_removedRemove-DlpPolicyo365_mailbox_audit_bypassSet-MailboxAuditBypassAssociationo365_file_malware_detectedFileMalwareDetectedo365_security_alert_addedAlertAddedAll validated through the
plugins/alertsoffline contract harness (TestAWSRawContracts+TestFilterAndRuleContractspass).Coordination
#2660and#2661(both touchfilters/aws/aws.yml,aws_contract_test.go,aws_raw.json,filter-contracts/aws.json, and the same O365 area). This PR should be rebased onto whichever of those merges first — the AWS rules assume his v1.1.x filter schema is final.