Skip to content
Threat Feed

January 2024 (30)

medium advisory

AWS IAM AccessDenied Discovery Events

Detection of excessive AccessDenied events within an hour for AWS IAM users, indicating a potential compromised access key used for unauthorized discovery actions.

AWS IAM aws cloudtrail iam accessdenied discovery
2r 1t
high advisory

AWS IAM Account Concurrent Sessions from Multiple IPs

Detection of AWS IAM accounts exhibiting concurrent sessions originating from different IP addresses within a short timeframe, potentially indicating session hijacking.

AWS IAM cloud aws iam session-hijacking
2r 1t
low advisory

AWS IAM API Calls via Temporary Session Tokens

Detection of AWS IAM API operations using temporary session credentials, indicating potential credential theft, session hijacking, or privileged role abuse for persistence and defense evasion.

AWS Identity and Access Management +2 cloud aws iam session-token persistence privilege-escalation
3r 2t
medium advisory

AWS IAM Customer Managed Policy Version Manipulation for Privilege Escalation

Successful creation of new or setting default versions of customer-managed IAM policies can indicate privilege escalation attempts by attackers modifying policy permissions.

Amazon Web Services privilege-escalation aws iam
2r 2t
medium advisory

AWS IAM Default Policy Version Modification

An adversary modifies the default version of an AWS IAM policy, potentially downgrading security or disrupting access control.

AWS Identity and Access Management aws iam policy
2r 1t
medium advisory

AWS IAM MFA Device Deactivation

Detection of AWS IAM MFA device deactivation via the `DeactivateMFADevice` API call, which could indicate an attempt to weaken account protections for privilege escalation or persistence.

AWS Identity and Access Management aws iam mfa deactivation cloudtrail
2r 3t
high advisory

AWS IAM Policy Default Version Manipulation

An adversary may set a default policy version in AWS IAM to potentially escalate privileges, especially if previous policy versions granted broader permissions, leading to unauthorized access and data breaches.

AWS Identity and Access Management aws iam privilege-escalation defense-evasion
2r 2t
medium advisory

AWS IAM Policy Deletion Detection

Detection of AWS IAM policy deletion events, which could indicate malicious activity by a compromised account or insider threat.

AWS IAM aws iam policy cloudtrail
2r 1t
high advisory

AWS IAM Policy Version Created Allowing Access to All Resources

An AWS IAM policy version allowing access to all resources has been created, potentially leading to privilege escalation and unauthorized actions.

AWS Identity and Access Management aws iam privilege-escalation cloudtrail
2r 1t
medium advisory

AWS IAM Principal Enumeration via UpdateAssumeRolePolicy

Detects repeated failed attempts to update an IAM role's trust policy in an AWS account, consistent with role and user enumeration techniques, potentially indicating attacker-controlled infrastructure or offensive tooling.

AWS IAM aws iam enumeration discovery credential-access
2r 3t
medium advisory

AWS IAM Session Token Used From Multiple Addresses

Compromised AWS IAM session tokens are used from multiple IP addresses, networks, cities, and user agents within a short timeframe, indicating potential credential theft and abuse.

IAM aws cloudtrail credential-theft initial-access
2r 1t
high advisory

AWS IAM UpdateLoginProfile Privilege Escalation

A user updating another user's login profile in AWS CloudTrail, potentially indicating privilege escalation.

AWS IAM aws iam privilege-escalation
2r 2t
medium advisory

AWS IAM Virtual MFA Device Registration Attempt with Session Token

An adversary with compromised temporary AWS credentials attempts to establish persistence by creating or enabling a virtual MFA device, bypassing expected session token usage.

IAM cloud aws persistence
2r 3t
high advisory

AWS KMS Key Creation with Public Encryption Policy

An attacker may create AWS KMS keys with a permissive encryption policy, granting `kms:Encrypt` permissions to all principals, potentially leading to unauthorized encryption and data compromise across multiple organizations.

AWS Key Management Service aws kms encryption misconfiguration ransomware
2r 1t
medium advisory

AWS Login Profile Creation Activity

Monitoring AWS login profile creation events can help identify potentially malicious user or role creation activities within an AWS environment.

AWS Identity and Access Management aws iam cloud privilege-escalation
2r 2t
high advisory

AWS Login Profile Creation Followed by Console Login

Detection of an AWS user creating a login profile for another user, followed by a console login from the same source IP, potentially indicating privilege escalation.

AWS CloudTrail +2 aws privilege-escalation persistence
2r 2t
high advisory

AWS Management Console Failed Login Attempts

Detection of repeated failed login attempts to the AWS Management Console, potentially indicating brute-force or credential access attempts by threat actors aiming to compromise AWS accounts.

AWS Management Console aws cloudtrail credential-access brute-force
2r 2t
high advisory

AWS Multi-Factor Authentication Disabled

Detection of AWS Multi-Factor Authentication (MFA) being disabled for an IAM user, indicating potential weakening of account security and persistence attempts.

AWS Identity and Access Management aws cloudtrail mfa iam persistence
2r 3t
high advisory

AWS Network Access Control List Created with All Open Ports

An AWS Network Access Control List (NACL) configured to allow all ports and protocols, potentially exposing resources to unauthorized access.

AWS Network Access Control List cloud aws network-acl misconfiguration
2r 1t
high advisory

AWS Network Access Control List Deletion Detected

Detection of AWS Network Access Control List (ACL) deletion events via CloudTrail logs indicates a potential attempt to weaken network security controls.

AWS Network Access Control List aws cloudtrail network-acl defense-evasion
3r 1t
high advisory

AWS Network ACL Deletion Detected

Detection of AWS Network Access Control List (ACL) deletion via CloudTrail logs indicating potential unauthorized access or data exfiltration.

AWS CloudTrail +3 cloud aws network-acl privilege-escalation
2r
medium advisory

AWS Network ACL Deletion Detection

Detection of AWS Network Access Control List (ACL) deletion via CloudTrail logs, potentially indicating malicious attempts to bypass network security controls and gain unauthorized access.

AWS cloudtrail network acl defense-evasion
2r 1t
medium advisory

AWS RDS DB Instance or Cluster Deleted

An adversary with sufficient permissions may delete RDS resources such as DB instances or clusters to impede recovery, destroy evidence, or inflict operational impact on the environment.

Amazon RDS +1 cloud aws rds datadestruction
2r 1t
high advisory

AWS Route 53 Domain Transfer Lock Disabled

The disabling of the transfer lock on an AWS Route 53 domain is detected, potentially indicating unauthorized domain transfer, takeover, or service disruption by an adversary gaining domain-management permissions.

Route 53 aws route53 domain-hijacking persistence
2r 3t
critical advisory

AWS S3 Bucket Public Access Configuration

Detection of publicly accessible AWS S3 buckets created via PutBucketAcl operations, potentially leading to unauthorized data access, tampering, or exfiltration.

Amazon S3 aws s3 bucket acl public misconfiguration data-breach
2r 1t
high advisory

AWS S3 Exfiltration Behavior Identified via Risk Correlation

This correlation identifies potential AWS S3 exfiltration behavior by correlating multiple risk events related to Collection and Exfiltration techniques, triggered when multiple analytics and distinct MITRE ATT&CK IDs are triggered for a specific risk object, indicating a potential data exfiltration attempt.

S3 +3 aws exfiltration cloud
2r 2t
high advisory

AWS Security Services Configuration Deletion

Detection of deletion of critical AWS Security Services configurations like CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules to evade detection, potentially leading to data breaches and unauthorized access.

CloudWatch +5 aws cloudtrail defense-evasion security-service
2r 1t
high advisory

AWS Security Services Impairment via Deletion of Resources

Detection of adversaries attempting to impair or disable AWS security services by deleting resources across GuardDuty, AWS WAF, CloudWatch, Route 53, and CloudWatch Logs to evade detection and remove visibility.

CloudWatch +5 aws cloudtrail defense-evasion cloud
2r 1t
high advisory

AWS Security Services Impairment via Deletion Operations

Attackers attempt to impair or disable AWS security services such as GuardDuty, WAF, CloudWatch, Route 53 and CloudWatch Logs by deleting detectors, rule groups, IP sets, web ACLs, logging configurations, alarms and log streams, in order to evade detection and operate undetected.

AWS GuardDuty +4 aws cloudtrail defense-evasion
3r 1t
medium advisory

AWS SNS Topic Message Publish by Rare User

This rule identifies when an SNS topic message is published by a rare user in AWS, which may indicate lateral movement, data exfiltration, or phishing campaigns, potentially leading to resource hijacking and impact on cloud services.

Amazon Simple Notification Service aws sns lateral-movement exfiltration impact
2r 4t