An identity attached an administrative policy to an IAM user or role
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Privilege Escalation (TA0004), Persistence (TA0003)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Roles (T1098.003)
Severity
Informational
Description
An identity attached an administrative policy to an IAM user or role.
Attacker's Goals
Escalate privileges in cloud environments.
Investigative actions
Confirm whether this activity was intentional.
Check for other API calls that were executed by the identity.
Look for any suspicious behavior from the IAM user or role to whom the administrative policy was attached.
Variations
PreviousAn identity accessed Azure Kubernetes Secrets
NextAn identity created or updated password for an IAM user
Was this helpful?
