For the complete documentation index, see llms.txt. This page is also available as Markdown.

An identity created or updated password for an IAM user

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Privilege Escalation (TA0004), Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Credentials (T1098.001)

Severity

Informational

Description

An identity created or updated an AWS console password for an IAM user.

Attacker's Goals

Escalate privileges, maintain persistence in cloud environments.

Investigative actions

  • Verify whether the identity should be making this action.

  • Examine what additional API calls were made by the identity.

Variations

A suspicious identity created or updated password for an IAM user

Synopsis

Field
Value

ATT&CK Tactic

Privilege Escalation (TA0004), Persistence (TA0003)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Credentials (T1098.001)

Severity

Low

Description

An identity created or updated an AWS console password for an IAM user.

Attacker's Goals

Escalate privileges, maintain persistence in cloud environments.

Investigative actions

  • Verify whether the identity should be making this action.

  • Examine what additional API calls were made by the identity.

Was this helpful?