ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
This reference table is part of the 3CORESec ECS-Cloudtrail project: https://github.com/3CORESec/ECS-CloudTrail
2
SourceSource Field or PatternECS FieldEXPORTED FIELDS - AWSCategoryCommentAvailable in Sigma
3
CloudTrailawsRegioncloud.regionECS - Cloud FieldsYES (ecs-cloutrail.yml)
4
CloudTraileventIDevent.idECS - Event FieldsYES (ecs-cloutrail.yml)
5
CloudTraileventNameevent.actionECS - Event FieldsYES (ecs-cloutrail.yml)
6
CloudTraileventSourceevent.providerECS - Event FieldsYES (ecs-cloutrail.yml)
7
CloudTraileventTime@timestampECS - Base FieldsYES (ecs-cloutrail.yml)
8
CloudTraileventTypeaws.cloudtrail.event_typeAWS - session_contextYES (ecs-cloutrail.yml)
9
CloudTrailrecipientAccountIdaws.cloudtrail.recipient_account_idAWS - resourcesYES (ecs-cloutrail.yml)
10
CloudTrailrequestIDaws.cloudtrail.request_idAWS - session_contextYES (ecs-cloutrail.yml)
11
CloudTrailrequestParametersaws.cloudtrail.request_parametersAWS - session_contextYES (ecs-cloutrail.yml)
12
CloudTrailresponseElementsaws.cloudtrail.response_elementsAWS - session_contextYES (ecs-cloutrail.yml)
13
CloudTrailsourceIPAddresssource.addressECS - Source FieldsYES (ecs-cloutrail.yml)
14
CloudTrailsourceIPAddresssource.geoECS - Geo FieldsYES (ecs-cloutrail.yml)
15
CloudTrailuserIdentity.accessKeyIdaws.cloudtrail.user_identity.access_key_idAWS - user_identityYES (ecs-cloutrail.yml)
16
CloudTrailuserIdentity.accountIdcloud.account.idECS - Cloud FieldsYES (ecs-cloutrail.yml)
17
CloudTrailuserIdentity.arnaws.cloudtrail.user_identity.arnAWS - user_identityYES (ecs-cloutrail.yml)
18
CloudTrailuserIdentity.invokedByaws.cloudtrail.user_identity.invoked_byAWS - session_contextYES (ecs-cloutrail.yml)
19
CloudTrailuserIdentity.principalIduser.idECS - User FieldsYES (ecs-cloutrail.yml)
20
CloudTrailuserIdentity.sessionContext.attributes.creationDateaws.cloudtrail.user_identity.session_context.creation_dateAWS - session_contextYES (ecs-cloutrail.yml)
21
CloudTrailuserIdentity.sessionContext.attributes.mfaAuthenticatedaws.cloudtrail.user_identity.session_context.mfa_authenticatedAWS - session_contextYES (ecs-cloutrail.yml)
22
CloudTrailuserAgentuser_agent.originalECS - User agent FieldsYES (ecs-cloutrail.yml)
23
CloudTrailvpcEndpointIdaws.cloudtrail.vpc_endpoint_idAWS - resourcesYES (ecs-cloutrail.yml)
24
CloudTrailerrorMessage aws.cloudtrail.error_messageAWS - session_contextYES (ecs-cloutrail.yml)
25
CloudTraileventVersionaws.cloudtrail.event_versionAWS - cloudtrailYES (ecs-cloutrail.yml)
26
CloudTrailsharedEventIdaws.cloudtrail.shared_event_idAWS - resourcesYES (ecs-cloutrail.yml)
27
CloudTrailuserIdentity.typeaws.cloudtrail.user_identity.typeAWS - user_identityYES (ecs-cloutrail.yml)
28
CloudTrailuserIdentity.userNameuser.nameECS - User FieldsYES (ecs-cloutrail.yml)
29
CloudTrailapiVersionaws.cloudtrail.api_versionAWS - session_contextYES (ecs-cloutrail.yml)
30
CloudTrailmanagementEventaws.cloudtrail.management_eventAWS - session_contextYES (ecs-cloutrail.yml)
31
CloudTrailreadOnlyaws.cloudtrail.read_onlyAWS - session_contextYES (ecs-cloutrail.yml)
32
CloudTrailresources.ARNaws.cloudtrail.resources.arnAWS - resourcesYES (ecs-cloutrail.yml)
33
CloudTrailresources.accountIdaws.cloudtrail.resources.account_idAWS - resourcesYES (ecs-cloutrail.yml)
34
CloudTrailresources.typeaws.cloudtrail.resources.typeAWS - resourcesYES (ecs-cloutrail.yml)
35
CloudTrailerrorCode AWS - session_contextYES (ecs-cloutrail.yml)
36
CloudTrailadditionalEventdataaws.cloudtrail.additional_eventdataAWS - session_contextYES (ecs-cloutrail.yml)
37
CloudTrailserviceEventDetails aws.cloudtrail.service_event_detailsAWS - resourcesYES (ecs-cloutrail.yml)
38
CloudTrailmessageevent.originalECS - Event FieldsYES (ecs-cloutrail.yml)
39
CloudTrailevent (processor set = static content)event.kindECS - Event FieldsYES (ecs-cloutrail.yml)
40
CloudTrailaws (processor set = static content)cloud.providerECS - Cloud FieldsYES (ecs-cloutrail.yml)
41
CloudTrailinfo (processor set = static content)event.typeECS - Event FieldsYES (ecs-cloutrail.yml)
42
CloudTrailauthentication (script if event.action=consoleLogin)event.categoryECS - Event FieldsYES (ecs-cloutrail.yml)
43
CloudTrail
script: authentication/failure or value from (aws.cloudtrail.response_elements)
event.outcomeECS - Event FieldsYES (ecs-cloutrail.yml)
44
VPC Flow Logs%{aws.vpcflow.version}aws.vpcflow.versionAWS - vpcflow
Direct transform to exported field from dissect expression
Not currently in Sigma
45
VPC Flow Logs%{cloud.account}cloud.account.idaws.vpcflow.account_id (for reference, not used)ECS - Cloud Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
46
VPC Flow Logs%{interface.id}interface.idaws.vpcflow.interface_id (for reference, not used)ECS - Interface Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
47
VPC Flow Logs%{source.address}source.addressaws.vpcflow.pkt_srcaddr (for reference, not used)ECS - Source Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
48
VPC Flow Logssource.addresssource.geoaws.vpcflow.pkt_srcaddr (for reference, not used)ECS - Source FieldsDirect transform to ECSNot currently in Sigma
49
VPC Flow Logs%{destination.address}destination.addressaws.vpcflow.pkt_dstaddr (for reference, not used)ECS - Destination Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
50
VPC Flow Logsdestination.addressdestination.geoaws.vpcflow.pkt_dstaddr (for reference, not used)ECS - Destination FieldsDirect transform to ECSNot currently in Sigma
51
VPC Flow Logs%{source.port}source.portECS - Source Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
52
VPC Flow Logs%{destination.port}destination.portECS - Destination Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
53
VPC Flow Logs%{network.iana_number}network.iana_numberaws.vpcflow.type (for reference, not used)ECS - Network Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
54
VPC Flow Logs%{network.packets}network.packetsECS - Network Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
55
VPC Flow Logs%{network.bytes}network.bytesECS - Network Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
56
VPC Flow Logs%{aws.vpcflow.start}event.startECS - Event Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
57
VPC Flow Logs%{aws.vpcflow.end}event.endECS - Event Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
58
VPC Flow Logs%{aws.vpcflow.end}@timestampECS - Base Fields
Direct transform to exported field from dissect expression
Not currently in Sigma
59
VPC Flow Logs%{aws.vpcflow.action}aws.vpcflow.actionAWS - vpcflow
Direct transform to exported field from dissect expression
Not currently in Sigma
60
VPC Flow Logs%{aws.vpcflow.log_status}aws.vpcflow.log_statusAWS - vpcflow
Direct transform to exported field from dissect expression
Not currently in Sigma
61
VPC Flow Logsaws (processor set = static content)cloud.providerECS - Cloud FieldsDirect transform to ECSNot currently in Sigma
62
VPC Flow Logsevent (processor set = static content)event.kindECS - Event FieldsDirect transform to ECSNot currently in Sigma
63
AWS TransferSigma mapping not planned
64
AWS TransferSigma mapping not planned
65
AWS TransferSigma mapping not planned
66
AWS TransferSigma mapping not planned
67
AWS TransferSigma mapping not planned
68
AWS TransferSigma mapping not planned
69
AWS TransferSigma mapping not planned
70
⚠️ AWS EC2 (LOCALHOST) LOGS NOT INCLUDED AS THIS PIPELINE IS MEANT TO BE EXECUTED FROM ELASTICSEARCH AND NOT EC2 ⚠️ Sigma mapping not planned
71
⚠️ AWS ELB ACCESS LOGS NOT INCLUDED AS LOGS ARE REQUIRED TO BE STORED IN S3 BUCKET AND NOT DISPATCHED TO CLOUDWATCH (cannot be picked up by Functionbeat) ⚠️ Sigma mapping not planned
72
⚠️ AWS S3 SERVER ACCESS LOGS NOT INCLUDED AS LOGS ARE REQUIRED TO BE STORED IN S3 BUCKET AND NOT DISPATCHED TO CLOUDWATCH (cannot be picked up by Functionbeat) ⚠️ Sigma mapping not planned
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100