A user logged in to the AWS console for the first time
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003), Lateral Movement (TA0008)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Credentials (T1098.001), Remote Services: Cloud Services (T1021.007)
Severity
Informational
Description
A user logged in to the AWS console for the first time.
Attacker's Goals
Evading detections by performing direct operations using the AWS console.
Performing non-automatic operations easily.
Investigative actions
Check if the identity is an AWS identity.
Investigate which operations were performed by the identity.
Variations
PreviousA user logged in from an abnormal country or ASN
NextA user logged on to multiple workstations via Schannel
Was this helpful?
