Azure / Azure/Azure-Sentinel

Proposal: ASIM-aligned AWS GuardDuty parser and hunting queries

Open
#14,768 2 comments 0 reactions 3 assignees Claimed by @hunngu-ms View on GitHub
ASIM enhancement Hunting Parser Solution
Dominant language
Python
Stars
6.1k
Forks
3.8k
Avg merge
4d 7h
Merged PRs (30d)
125

Description

I have developed and validated an ASIM-aligned parsing layer for AWS GuardDuty findings ingested through the existing Microsoft Sentinel AWS connector. The proposed contribution would extend the current AWS solution with:

- an ASIM Network Session parser (`ASimNetworkSessionAWSGuardDuty`)
- hunting queries for high-severity findings, EKS privilege escalation/credential access, and S3 public exposure
- validation against the existing `AWSGuardDuty` table schema and the current AWS S3 connector

This proposal does not replace the existing AWS connector or the existing `AWSGuardDuty - GuardDuty Alert` analytic rule. It adds structured ASIM parsing and hunting content on top of the existing `AWSGuardDuty` table. I'd welcome guidance on whether this should be folded into the existing Amazon Web Services solution or submitted as standalone content.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.