Rules: AWS - New UserPoolClient Created Description A UserPoolClient is an entity that has permission to call unauthenticated API operations (operations that do not have an authenticated user). Additional Details Detail Value Type Templated Match Category Execution Apply Risk to Entities device_hostname, device_ip, user_username, srcDevice_ip Signal Name AWS - New UserPoolClient Created Summary Expression {{action}}: {{application}} performed by user: {{user_username}} Score/Severity Static: 1 Enabled by Default True Prototype False Tags _mitreAttackTactic:TA0002, _mitreAttackTactic:TA0005, _mitreAttackTactic:TA0008, _mitreAttackTechnique:T1550, _mitreAttackTechnique:T1550.001 Vendors and Products Amazon AWS - CloudTrail Fields Used Origin Field Normalized Schema device_hostname Normalized Schema device_ip Normalized Schema metadata_deviceEventId Normalized Schema metadata_product Normalized Schema metadata_vendor Normalized Schema srcDevice_ip Normalized Schema user_username