AWS Secrets Manager discovery
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006), Discovery (TA0007)
ATT&CK Technique
Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006), Cloud Service Discovery (T1526)
Severity
Informational
Description
An attempt was made to list secrets from AWS Secrets Manager.
Attacker's Goals
Exfiltrate sensitive secrets stored in AWS Secrets Manager.
Investigative actions
Check if the secrets manager activity aligns with known workflows or automation, or if it indicates abnormal activity.
Follow further actions done by the identity.
Variations
PreviousAWS S3 Buckets enumeration activity
NextAWS Security Group remote access allowed from an unknown external IP address
Was this helpful?
