Unusual AWS user added to group
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Account Manipulation (T1098)
Severity
Low
Description
AWS user added to AWS group, possibly to elevate privileges and gain more access to resources.
Attacker's Goals
Gain persistence and elevate privileges.
Investigative actions
Check if the action was done using an automation service.
Check if there are any other suspicious activities originated from the same machine/executing user.
Variations
Was this helpful?
