AWS console login without MFA
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003), Credential Access (TA0006)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Credentials (T1098.001), Multi-Factor Authentication Request Generation (T1621)
Severity
Informational
Description
An identity logged in to the AWS console without MFA.
Attacker's Goals
Bypassing multifactor authentication controls to gain unauthorized access to the cloud environment.
Investigative actions
Determine why MFA was not enforced and whether MFA was ever enabled.
Track any subsequent activity performed by the identity after the login to identify potential misuse.
Was this helpful?
