AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation: Additional Cloud Roles (T1098.003), Account Manipulation (T1098)
Severity
Low
Description
A cloud identity has updated an IAM role's trust policy to allow external AWS account access.
Attacker's Goals
Obtaining persistency by assuming a role in the target's environment.
Investigative actions
Investigate any unusual activity originating from the suspected identity.
Investigate any unusual activity performed in the assumed role sessions when originating from the allowed added accounts.
Validate the legitimacy of the AWS accounts that were allowed external access.
Was this helpful?
