Unusual resource modification by newly seen IAM user
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
OCI Analytics
ATT&CK Tactic
Persistence (TA0003), Privilege Escalation (TA0004), Impact (TA0040)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Data Destruction (T1485)
Severity
Informational
Description
A cloud resource was modified by a newly seen IAM user.
Attacker's Goals
Leverage access to manipulate cloud infrastructure.
Investigative actions
Examine which resources were affected and how.
Investigate any unusual activity originating from the identity.
Variations
Was this helpful?
