New cloud identity created with administrative policy
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Create Account: Cloud Account (T1136.003), Create Account (T1136), Account Manipulation: Additional Cloud Credentials (T1098.001)
Severity
Low
Description
New cloud identity was created and assigned administrative policy.
Attacker's Goals
Escalate privileges in cloud environments.
Investigative actions
Confirm whether this activity was intentional.
Check for other API calls that were executed by the identity.
Look for any suspicious behavior from the IAM user/role to whom the administrative policy was attached.
Variations
Was this helpful?
