For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS console login without MFA

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Initial Access (TA0001), Persistence (TA0003), Credential Access (TA0006)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Account Manipulation: Additional Cloud Credentials (T1098.001), Multi-Factor Authentication Request Generation (T1621)

Severity

Informational

Description

An identity logged in to the AWS console without MFA.

Attacker's Goals

Bypassing multifactor authentication controls to gain unauthorized access to the cloud environment.

Investigative actions

  • Determine why MFA was not enforced and whether MFA was ever enabled.

  • Track any subsequent activity performed by the identity after the login to identify potential misuse.

Was this helpful?