Skip to content

Latest commit

 

History

History
26 lines (20 loc) · 995 Bytes

3.11.md

File metadata and controls

26 lines (20 loc) · 995 Bytes

3.11 - Unusual number of firewall rules modified in the last 7 days

Unusual number of firewall rules modified on any given day in the last 7 days, where unusual is defined as daily_count > avg(daily_count) + 2 * stddev(daily_count), and daily_count is the number of change actions on a given day. Aggregate averages and standard deviations are computed for each day looking back at the preceding daily counts. Default lookback window is the last 90 days.

Category: Cloud Provisioning Activity
Use Cases: Detect
Data Sources: Audit Logs - Admin Activity

Queries or Rules

BigQuery Chronicle
SQL Contribute rule

Event Generation

No event generation steps provided. Contribute emulation test to this use case.

Sample Event

No log samples provided. Contribute log samples to this use case.