diff --git a/rules/aws_cloudtrail_rules/aws_cloudtrail_event_selectors_disabled.yml b/rules/aws_cloudtrail_rules/aws_cloudtrail_event_selectors_disabled.yml index e261eccff..fa3a1d4d1 100644 --- a/rules/aws_cloudtrail_rules/aws_cloudtrail_event_selectors_disabled.yml +++ b/rules/aws_cloudtrail_rules/aws_cloudtrail_event_selectors_disabled.yml @@ -16,7 +16,7 @@ Reports: - TA0005:T1562 Severity: Medium Description: > - A CloudTrail Trail was modified. + A CloudTrail Trail was modified to exclude management events for 1 or more resource types. Runbook: https://docs.runpanther.io/alert-runbooks/built-in-rules/aws-cloudtrail-modified Reference: https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-update-a-trail-console.html SummaryAttributes: