An identity created or updated password for an IAM user
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Privilege Escalation (TA0004), Persistence (TA0003)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Credentials (T1098.001)
Severity
Informational
Description
An identity created or updated an AWS console password for an IAM user.
Attacker's Goals
Escalate privileges, maintain persistence in cloud environments.
Investigative actions
Verify whether the identity should be making this action.
Examine what additional API calls were made by the identity.
Variations
PreviousAn identity attached an administrative policy to an IAM user or role
NextAn identity disabled bucket logging
Was this helpful?
