For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cloud impersonation attempt by unusual identity type

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078), Trusted Relationship (T1199)

Severity

Informational

Description

A suspicious identity type has attempted to impersonate another identity.

Attacker's Goals

  • Escalate privileges to bypass access controls

  • Avoid detection throughout their compromise.

Investigative actions

  • Check the identity's designation.

  • Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.

Variations

Cloud impersonation attempt of a management role by unusual identity type

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078), Trusted Relationship (T1199)

Severity

Informational

Description

An unusual cloud identity type attempted to impersonate a management role.

Attacker's Goals

  • Escalate privileges to bypass access controls

  • Avoid detection throughout their compromise.

Investigative actions

  • Check the identity's designation.

  • Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.

Successful cloud impersonation by an unusual identity type

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078), Trusted Relationship (T1199)

Severity

Medium

Description

A suspicious identity type has successfully impersonated another identity.

Attacker's Goals

  • Escalate privileges to bypass access controls

  • Avoid detection throughout their compromise.

Investigative actions

  • Check the identity's designation.

  • Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.

Was this helpful?