AWS Excessive Security Scanning

AWS Excessive Security Scanning

Description

This search looks for AWS CloudTrail events and analyse the amount of eventNames which starts with Describe by a single user. This indicates that this user scans the configuration of your AWS cloud environment.

   Help

AWS Excessive Security Scanning Help

You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs.

   Search

Open in Search