Tag
high
advisory
AWS SecurityHub Findings Evasion via API Calls
3 rules 2 TTPsAttackers can impair defenses by modifying or deleting findings and insights within AWS SecurityHub using API calls such as BatchUpdateFindings, DeleteInsight, UpdateFindings, and UpdateInsight.
AWS Security Hub
aws
cloud
securityhub
defense-evasion
3r
2t
medium
advisory
Spike in AWS Security Hub Alerts for EC2 Instance
2 rules 6 TTPsDetects a sudden increase in security alerts generated by AWS Security Hub related to a specific EC2 instance, potentially indicating active compromise or misconfiguration.
EC2
cloud
aws
securityhub
alert-spike
2r
6t