For the complete documentation index, see llms.txt. This page is also available as Markdown.

An identity attached an administrative policy to an IAM user or role

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Privilege Escalation (TA0004), Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Informational

Description

An identity attached an administrative policy to an IAM user or role.

Attacker's Goals

Escalate privileges in cloud environments.

Investigative actions

  • Confirm whether this activity was intentional.

  • Check for other API calls that were executed by the identity.

  • Look for any suspicious behavior from the IAM user or role to whom the administrative policy was attached.

Variations

An identity attached an administrative policy to itself

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004), Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Medium

Description

An identity attached an administrative policy to an IAM user or role.

Attacker's Goals

Escalate privileges in cloud environments.

Investigative actions

  • Confirm whether this activity was intentional.

  • Check for other API calls that were executed by the identity.

  • Look for any suspicious behavior from the IAM user or role to whom the administrative policy was attached.

An identity failed to attach an administrative policy to an IAM user or role

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004), Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Medium

Description

An identity attached an administrative policy to an IAM user or role.

Attacker's Goals

Escalate privileges in cloud environments.

Investigative actions

  • Confirm whether this activity was intentional.

  • Check for other API calls that were executed by the identity.

  • Look for any suspicious behavior from the IAM user or role to whom the administrative policy was attached.

A suspicious identity attached an administrative policy to an IAM user/role

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004), Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Roles (T1098.003)

Severity

Low

Description

An identity attached an administrative policy to an IAM user or role.

Attacker's Goals

Escalate privileges in cloud environments.

Investigative actions

  • Confirm whether this activity was intentional.

  • Check for other API calls that were executed by the identity.

  • Look for any suspicious behavior from the IAM user or role to whom the administrative policy was attached.

Was this helpful?