Unusual IAM enumeration activity by a non-user Identity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Account Discovery (T1087), Permission Groups Discovery (T1069), Cloud Service Discovery (T1526)
Severity
Informational
Description
An unusual command which may be related to an IAM recon enumeration was executed by a non-user identity.
Attacker's Goals
Collect information on the cloud environment, including IAM users, groups, roles, and policies.
Investigative actions
Check if the API call was made by the identity. Check if there are additional unusual API calls from the identity.
PreviousUnusual hostname for the sending mail server in the email headers
NextUnusual Identity and Access Management (IAM) activity
Was this helpful?
