Detection rules › Kusto

AWSCloudTrail - ECR image scan findings high or critical

Status
available
Severity
high
Time window
1d
Source
github.com/Azure/Azure-Sentinel

Identifies Amazon ECR image scan findings that report high or critical severity vulnerabilities. These findings indicate container images that should be reviewed and remediated before deployment or continued use.

MITRE ATT&CK coverage

TacticTechniques
Discovery

Telemetry coverage

Rule body

id: f6928301-56da-4d2c-aabe-e1a552bc8892
name: AWSCloudTrail - ECR image scan findings high or critical
description: |
  Identifies Amazon ECR image scan findings that report high or critical severity vulnerabilities. These findings indicate container images that should be reviewed and remediated before deployment or continued use.
severity: High
status: Available
requiredDataConnectors:
  - connectorId: AWS
    dataTypes:
      - AWSCloudTrail
queryFrequency: 1d
queryPeriod: 1d
triggerOperator: gt
triggerThreshold: 0
tactics:
  - Discovery
relevantTechniques:
  - T1083
query: |
    AWSCloudTrail
    | where EventName == "DescribeImageScanFindings" and isempty(ErrorCode) and isempty(ErrorMessage)
    | extend repoName = tostring(parse_json(ResponseElements).repositoryName)
    | extend imageId = tostring(parse_json(ResponseElements).imageId.imageDigest)
    | extend Critical = toint(parse_json(ResponseElements).imageScanFindings.findingSeverityCounts.CRITICAL)
    | extend High = toint(parse_json(ResponseElements).imageScanFindings.findingSeverityCounts.HIGH)
    | where Critical > 0 or High > 0
    | extend UserIdentityArn = iif(isempty(UserIdentityArn), tostring(parse_json(Resources)[0].ARN), UserIdentityArn)
    | extend UserName = tostring(split(UserIdentityArn, '/')[-1])
    | extend AccountName = case( UserIdentityPrincipalid == "Anonymous", "Anonymous", isempty(UserIdentityUserName), UserName, UserIdentityUserName)
    | extend AccountName = iif(AccountName contains "@", tostring(split(AccountName, '@', 0)[0]), AccountName),
      AccountUPNSuffix = iif(AccountName contains "@", tostring(split(AccountName, '@', 1)[0]), "")
entityMappings:
  - entityType: Account
    fieldMappings:
      - identifier: Name
        columnName: AccountName
      - identifier: UPNSuffix
        columnName: AccountUPNSuffix
      - identifier: CloudAppAccountId
        columnName: RecipientAccountId
  - entityType: IP
    fieldMappings:
      - identifier: Address
        columnName: SourceIpAddress
customDetails:
  Repository: repoName
  ImageDigest: imageId
  CriticalFindings: Critical
  HighFindings: High
alertDetailsOverride:
  alertDisplayNameFormat: 'AWS ECR image scan findings with high or critical Vulnerabilities in {{repoName}}'
  alertDescriptionFormat: 'ECR image {{imageId}} in repository {{repoName}} returned critical and high findings.'
version: 1.0.3
kind: Scheduled

Stages and Predicates

Stage 1: source

AWSCloudTrail

Stage 2: where

| where EventName == "DescribeImageScanFindings" and isempty(ErrorCode) and isempty(ErrorMessage)

Stage 3: extend (4 consecutive steps)

| extend repoName = tostring(parse_json(ResponseElements).repositoryName)
| extend imageId = tostring(parse_json(ResponseElements).imageId.imageDigest)
| extend Critical = toint(parse_json(ResponseElements).imageScanFindings.findingSeverityCounts.CRITICAL)
| extend High = toint(parse_json(ResponseElements).imageScanFindings.findingSeverityCounts.HIGH)

Stage 4: where

| where Critical > 0 or High > 0

Stage 5: extend (4 consecutive steps)

| extend UserIdentityArn = iif(isempty(UserIdentityArn), tostring(parse_json(Resources)[0].ARN), UserIdentityArn)
| extend UserName = tostring(split(UserIdentityArn, '/')[-1])
| extend AccountName = case( UserIdentityPrincipalid == "Anonymous", "Anonymous", isempty(UserIdentityUserName), UserName, UserIdentityUserName)
| extend AccountName = iif(AccountName contains "@", tostring(split(AccountName, '@', 0)[0]), AccountName),
  AccountUPNSuffix = iif(AccountName contains "@", tostring(split(AccountName, '@', 1)[0]), "")

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
repoNameextend
imageIdextend
Criticalextend
Highextend
UserIdentityArnextend
UserNameextend
AccountNameextend
AccountUPNSuffixextend