Vendor: Amazon

April 15, 2026 · View on GitHub

Product: VPC Flow Logs

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
5620623
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Lateral Movementnetwork-connection-failed
amazon-awsvpc-json-network-traffic-success-amazonvpc
amazon-awsvpc-str-network-traffic-fail-reject
amazon-awsvpc-sk4-network-traffic-success-transitgateway

network-connection-successful
amazon-awsvpc-json-network-traffic-success-amazonvpc
amazon-awsvpc-str-network-traffic-success-accept
amazon-awsvpc-sk4-network-traffic-success-transitgateway
T1071 - Application Layer Protocol
T1090 - Proxy
T1090.003 - Proxy: Multi-hop Proxy
T1190 - Exploit Public Fasing Application
TA0010 - TA0010
TA0011 - TA0011
  • 56 Rules
  • 20 Models
Malwarenetwork-connection-failed
amazon-awsvpc-json-network-traffic-success-amazonvpc
amazon-awsvpc-str-network-traffic-fail-reject
amazon-awsvpc-sk4-network-traffic-success-transitgateway

network-connection-successful
amazon-awsvpc-json-network-traffic-success-amazonvpc
amazon-awsvpc-str-network-traffic-success-accept
amazon-awsvpc-sk4-network-traffic-success-transitgateway
TA0011 - TA0011
  • 4 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Exploit Public Fasing Application

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy