Proposal: ASIM-aligned AWS GuardDuty parser and hunting queries
- Dominant language
- Python
- Stars
- 6.1k
- Forks
- 3.8k
- Avg merge
- 4d 7h
- Merged PRs (30d)
- 125
Description
I have developed and validated an ASIM-aligned parsing layer for AWS GuardDuty findings ingested through the existing Microsoft Sentinel AWS connector. The proposed contribution would extend the current AWS solution with:
- an ASIM Network Session parser (`ASimNetworkSessionAWSGuardDuty`)
- hunting queries for high-severity findings, EKS privilege escalation/credential access, and S3 public exposure
- validation against the existing `AWSGuardDuty` table schema and the current AWS S3 connector
This proposal does not replace the existing AWS connector or the existing `AWSGuardDuty - GuardDuty Alert` analytic rule. It adds structured ASIM parsing and hunting content on top of the existing `AWSGuardDuty` table. I'd welcome guidance on whether this should be folded into the existing Amazon Web Services solution or submitted as standalone content.
Contributor guide
Assessment
This issue has not been assessed yet.