WorkDocs

eventNameDescriptionSampleRule
anyCatch-all entry for WorkDocs rules that match the service but not a specific eventName.NN
AbortDocumentVersionUploadAborts the upload of the specified document version that was previously initiated by InitiateDocumentVersionUpload.NN
ActivateUserActivates the specified user.NN
AddResourcePermissionsCreates a set of permissions for the specified folder or document.NN
CreateCommentAdds a new comment to the specified document version.NN
CreateCustomMetadataAdds one or more custom properties to the specified resource (a folder, document, or version).NN
CreateFolderCreates a folder with the specified name and parent folder.NN
CreateLabelsAdds the specified list of labels to the given resource (a document or folder)NN
CreateNotificationSubscriptionConfigure Amazon WorkDocs to use Amazon SNS notifications.NN
CreateUserCreates a user in a Simple AD or Microsoft AD directory.NY
DeactivateUserDeactivates the specified user, which revokes the user's access to Amazon WorkDocs.NN
DeleteCommentDeletes the specified comment from the document version.NN
DeleteCustomMetadataDeletes custom metadata from the specified resource.NN
DeleteDocumentPermanently deletes the specified document and its associated metadata.NN
DeleteDocumentVersionDeletes a specific version of a document.NN
DeleteFolderPermanently deletes the specified folder and its contents.NN
DeleteFolderContentsDeletes the contents of the specified folder.NN
DeleteLabelsDeletes the specified list of labels from a resource.NN
DeleteNotificationSubscriptionDeletes the specified subscription from the specified organization.NN
DeleteUserDeletes the specified user from a Simple AD or Microsoft AD directory.NY
DescribeActivitiesDescribes the user activities in a specified time period.NN
DescribeCommentsList all the comments for the specified document version.NN
DescribeDocumentVersionsRetrieves the document versions for the specified document.NN
DescribeFolderContentsDescribes the contents of the specified folder, including its documents and subfolders.NN
DescribeGroupsDescribes the groups specified by the query.NN
DescribeNotificationSubscriptionsLists the specified notification subscriptions.NN
DescribeResourcePermissionsDescribes the permissions of a specified resource.NN
DescribeRootFoldersDescribes the current user's special folders; the RootFolder and the RecycleBin.NN
DescribeUsersDescribes the specified users.NN
GetCurrentUserRetrieves details of the current user for whom the authentication token was generated.NN
GetDocumentRetrieves details of a document.NN
GetDocumentPathRetrieves the path information (the hierarchy from the root folder) for the requested document.NN
GetDocumentVersionRetrieves version metadata for the specified document.NN
GetFolderRetrieves the metadata of the specified folder.NN
GetFolderPathRetrieves the path information (the hierarchy from the root folder) for the specified folder.NN
GetResourcesRetrieves a collection of resources, including folders and documents.NN
InitiateDocumentVersionUploadCreates a new document object and version object.NN
RemoveAllResourcePermissionsRemoves all the permissions from the specified resource.NN
RemoveResourcePermissionRemoves the permission for the specified principal from the specified resource.NN
RestoreDocumentVersionsRecovers a deleted version of an Amazon WorkDocs document.NN
SearchResourcesSearches metadata and the content of folders, documents, document versions, and comments.NN
UpdateDocumentUpdates the specified attributes of a document.NN
UpdateDocumentVersionChanges the status of the document version to ACTIVE.NN
UpdateFolderUpdates the specified attributes of the specified folder.NN
UpdateUserUpdates the specified attributes of the specified user, and grants or revokes administrative privileges to the Amazon WorkDocs site.NN

any: WorkDocs (catch-all)

#
Service
workdocs

Description

Catch-all entry for WorkDocs rules that match the service but not a specific eventName.

AbortDocumentVersionUpload

#
Service
workdocs

Description

Aborts the upload of the specified document version that was previously initiated by InitiateDocumentVersionUpload.

ActivateUser

#
Service
workdocs

Description

Activates the specified user.

AddResourcePermissions

#
Service
workdocs

Description

Creates a set of permissions for the specified folder or document.

CreateComment

#
Service
workdocs

Description

Adds a new comment to the specified document version.

CreateCustomMetadata

#
Service
workdocs

Description

Adds one or more custom properties to the specified resource (a folder, document, or version).

CreateFolder

#
Service
workdocs

Description

Creates a folder with the specified name and parent folder.

CreateLabels

#
Service
workdocs

Description

Adds the specified list of labels to the given resource (a document or folder)

CreateNotificationSubscription

#
Service
workdocs

Description

Configure Amazon WorkDocs to use Amazon SNS notifications.

CreateUser

#
Service
workdocs

Description

Creates a user in a Simple AD or Microsoft AD directory.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • High-Risk Cross-Cloud User Impersonation source medium: This detection focuses on identifying high-risk cross-cloud activities and sign-in anomalies that may indicate potential security threats. The query starts by analyzing Microsoft Entra ID Signin Logs to pinpoint instances where specific applications, risk levels, and result types align. It then correlates this information with relevant AWS CloudTrail events to identify activities across Azure and AWS environments.T1078, T1078.002, T1078.004, T1134↳ also matches DeleteUser

DeactivateUser

#
Service
workdocs

Description

Deactivates the specified user, which revokes the user's access to Amazon WorkDocs.

DeleteComment

#
Service
workdocs

Description

Deletes the specified comment from the document version.

DeleteCustomMetadata

#
Service
workdocs

Description

Deletes custom metadata from the specified resource.

DeleteDocument

#
Service
workdocs

Description

Permanently deletes the specified document and its associated metadata.

DeleteDocumentVersion

#
Service
workdocs

Description

Deletes a specific version of a document.

DeleteFolder

#
Service
workdocs

Description

Permanently deletes the specified folder and its contents.

DeleteFolderContents

#
Service
workdocs

Description

Deletes the contents of the specified folder.

DeleteLabels

#
Service
workdocs

Description

Deletes the specified list of labels from a resource.

DeleteNotificationSubscription

#
Service
workdocs

Description

Deletes the specified subscription from the specified organization.

DeleteUser

#
Service
workdocs

Description

Deletes the specified user from a Simple AD or Microsoft AD directory.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

  • High-Risk Cross-Cloud User Impersonation source medium: This detection focuses on identifying high-risk cross-cloud activities and sign-in anomalies that may indicate potential security threats. The query starts by analyzing Microsoft Entra ID Signin Logs to pinpoint instances where specific applications, risk levels, and result types align. It then correlates this information with relevant AWS CloudTrail events to identify activities across Azure and AWS environments.T1078, T1078.002, T1078.004, T1134↳ also matches CreateUser

DescribeActivities

#
Service
workdocs

Description

Describes the user activities in a specified time period.

DescribeComments

#
Service
workdocs

Description

List all the comments for the specified document version.

DescribeDocumentVersions

#
Service
workdocs

Description

Retrieves the document versions for the specified document.

DescribeFolderContents

#
Service
workdocs

Description

Describes the contents of the specified folder, including its documents and subfolders.

DescribeGroups

#
Service
workdocs

Description

Describes the groups specified by the query.

DescribeNotificationSubscriptions

#
Service
workdocs

Description

Lists the specified notification subscriptions.

DescribeResourcePermissions

#
Service
workdocs

Description

Describes the permissions of a specified resource.

DescribeRootFolders

#
Service
workdocs

Description

Describes the current user's special folders; the RootFolder and the RecycleBin.

DescribeUsers

#
Service
workdocs

Description

Describes the specified users.

GetCurrentUser

#
Service
workdocs

Description

Retrieves details of the current user for whom the authentication token was generated.

GetDocument

#
Service
workdocs

Description

Retrieves details of a document.

GetDocumentPath

#
Service
workdocs

Description

Retrieves the path information (the hierarchy from the root folder) for the requested document.

GetDocumentVersion

#
Service
workdocs

Description

Retrieves version metadata for the specified document.

GetFolder

#
Service
workdocs

Description

Retrieves the metadata of the specified folder.

GetFolderPath

#
Service
workdocs

Description

Retrieves the path information (the hierarchy from the root folder) for the specified folder.

GetResources

#
Service
workdocs

Description

Retrieves a collection of resources, including folders and documents.

InitiateDocumentVersionUpload

#
Service
workdocs

Description

Creates a new document object and version object.

RemoveAllResourcePermissions

#
Service
workdocs

Description

Removes all the permissions from the specified resource.

RemoveResourcePermission

#
Service
workdocs

Description

Removes the permission for the specified principal from the specified resource.

RestoreDocumentVersions

#
Service
workdocs

Description

Recovers a deleted version of an Amazon WorkDocs document.

SearchResources

#
Service
workdocs

Description

Searches metadata and the content of folders, documents, document versions, and comments.

UpdateDocument

#
Service
workdocs

Description

Updates the specified attributes of a document.

UpdateDocumentVersion

#
Service
workdocs

Description

Changes the status of the document version to ACTIVE.

UpdateFolder

#
Service
workdocs

Description

Updates the specified attributes of the specified folder.

UpdateUser

#
Service
workdocs

Description

Updates the specified attributes of the specified user, and grants or revokes administrative privileges to the Amazon WorkDocs site.