Cloud access key creation
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation: Additional Cloud Credentials (T1098.001)
Severity
Informational
Description
Cloud access key creation by a cloud identity.
Attacker's Goals
Persist in the environment.
Investigative actions
investigate the identity who created the access keys.
Check the access key activity in the organization.
Variations
PreviousClickFix - PowerShell executed through the run application
NextCloud activity from a high-risk IP address
Was this helpful?
