Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add guardduty critical #1526

Merged
merged 3 commits into from
Mar 4, 2025
Merged

Add guardduty critical #1526

merged 3 commits into from
Mar 4, 2025

Conversation

dgwhited
Copy link
Contributor

Background

Amazon GuardDuty has recently released composite attack sequence findings, which use the severity level 9.0. Previously the max severity number for detections was 8.9.

Changes

  • Adds GuardDuty critical detection

Testing

  • Detection has unit tests from Amazon GuardDuty sample findings.

@dgwhited dgwhited requested a review from a team as a code owner February 25, 2025 21:18
@arielkr256 arielkr256 added the rules Real-time log data detections label Mar 4, 2025
Copy link
Contributor

@arielkr256 arielkr256 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great, thank you!

@arielkr256 arielkr256 enabled auto-merge March 4, 2025 16:45
@arielkr256 arielkr256 disabled auto-merge March 4, 2025 16:45
@arielkr256 arielkr256 enabled auto-merge March 4, 2025 16:46
@arielkr256 arielkr256 added this pull request to the merge queue Mar 4, 2025
Merged via the queue into panther-labs:develop with commit be4a294 Mar 4, 2025
6 of 7 checks passed
akozlovets098 pushed a commit that referenced this pull request Mar 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
rules Real-time log data detections
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants