For the complete documentation index, see llms.txt. This page is also available as Markdown.

IAM Enumeration sequence

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

7 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069), Cloud Service Discovery (T1526)

Severity

Informational

Description

An identity has executed a sequence of events which may be related to an IAM recon enumeration.

Attacker's Goals

Gather information about the cloud environment, including IAM users, groups, roles, and policies.

Investigative actions

Verify whether the API calls were made by the identity and check for any additional related calls.

Variations

IAM Enumeration sequence executed from a cloud Internet facing instance

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery (T1087), Permission Groups Discovery (T1069), Cloud Service Discovery (T1526)

Severity

Low

Description

A cloud Internet facing instance performed an unusual IAM enumeration.

Attacker's Goals

Gather information about the cloud environment, including IAM users, groups, roles, and policies.

Investigative actions

Verify whether the API calls were made by the identity and check for any additional related calls.

Was this helpful?