A compute-attached identity executed API calls outside the instance's region
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Initial Access (TA0001), Credential Access (TA0006)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Steal Application Access Token (T1528), Unsecured Credentials (T1552)
Severity
Informational
Description
A compute-attached identity performed actions outside the compute instance region.
Attacker's Goals
Exfiltrate token and abuse it remotely.
Investigative actions
Verify whether the compute-attached identity's credentials were intentionally used remotely.
Check what API calls were executed using instance's attached role.
Check if the suspected instance is compromised.
Variations
PreviousA compromised process accessed a rare external host
NextA computer account was promoted to DC
Was this helpful?
