Defense Evasion (TA0005)(external, opens in a new tab or window)
text code block:data_stream.dataset: "aws.cloudtrail" and event.provider: "ec2.amazonaws.com" and event.action: ("CreateNetworkAclEntry" or "ReplaceNetworkAclEntry") and not aws.cloudtrail.user_identity.type: "AWSService" and event.outcome: ("success" or "failure") and aws.cloudtrail.flattened.request_parameters.aclProtocol: "-1" and aws.cloudtrail.flattened.request_parameters.ruleAction: "allow" and not user_agent.original: (*Terraform* or *terraform* or "cloudformation.amazonaws.com" or *pulumi* or *Pulumi*)
Install detection rules in Elastic Security
Detect AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).