1 Answer
- Newest
- Most votes
- Most comments
1
In order to troubleshooting ATD False Positives in your case for an centralized egress, please check on the below steps:
- Configure HOME_NET: Include remote workload subnets at policy level for proper rule matching
- Use Pass Rules: Insert strict order pass rules above ATD managed rule group for selective allowlisting
- Enable Alert Logging: Capture signature ID, threat metadata, protocol details, and verdicts
- Mitigation Priority: Pass rules (preferred) > Alert mode > Never remove rule group
Note/points to focus on:
- ATD rules are primarily egress (HOME_NET → EXTERNAL_NET)
- Requires 15,000 capacity units (increase quota to 50,000 if needed)
- Use DescribeRuleGroupMetadata API for threat indicator details, since ATD rules not directly visible.
Relevant content
asked 2 years ago
asked 2 years ago
- AWS OFFICIALUpdated 7 months ago
