For the complete documentation index, see llms.txt. This page is also available as Markdown.

MFA device was removed/deactivated from an IAM user

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Informational

Description

Deactivate an MFA device and disassociate it from an IAM user.

Attacker's Goals

This may allow an attacker to gain access to the IAM user.

Investigative actions

  • Check if IAM requires MFA to be enabled.

Was this helpful?