For the complete documentation index, see llms.txt. This page is also available as Markdown.

New cloud identity created with administrative policy

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Create Account: Cloud Account (T1136.003), Create Account (T1136), Account Manipulation: Additional Cloud Credentials (T1098.001)

Severity

Low

Description

New cloud identity was created and assigned administrative policy.

Attacker's Goals

Escalate privileges in cloud environments.

Investigative actions

  • Confirm whether this activity was intentional.

  • Check for other API calls that were executed by the identity.

  • Look for any suspicious behavior from the IAM user/role to whom the administrative policy was attached.

Variations

Administrative IAM User Created with Credentials

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Create Account: Cloud Account (T1136.003), Create Account (T1136), Account Manipulation: Additional Cloud Credentials (T1098.001)

Severity

Low

Description

New cloud identity was created and assigned administrative policy.

Attacker's Goals

Escalate privileges in cloud environments.

  • Maintain persistence in cloud environments.

Investigative actions

  • Confirm whether this activity was intentional.

  • Check for other API calls that were executed by the identity.

  • Look for any suspicious behavior from the IAM user/role to whom the administrative policy was attached.

  • Examine what additional API calls were made by the identity or by the newly created access token.

Was this helpful?