September 2026 (30)
Detection of Unauthorized AWS Route 53 Private Hosted Zone Associations
1 rule 3 TTPsAdversaries with high-level IAM permissions may associate unauthorized VPCs with AWS Route 53 private hosted zones to intercept internal DNS traffic, establish persistence, or perform reconnaissance.
Detection of AWS Route 53 Resolver Query Log Deletion
2 rules 3 TTPsAdversaries may delete Amazon Route 53 Resolver Query Log configurations to evade detection by disabling DNS query and response logging for VPC-based resources.
Detection of Unauthorized Public Exposure of AWS RDS Instances
1 rule 2 TTPsAdversaries with compromised AWS credentials may set the publiclyAccessible attribute to true during RDS instance creation or modification to facilitate data exfiltration, establish persistence, or bypass internal network boundaries.
Abuse of AWS IAM Roles Anywhere via External Trust Anchors
1 rule 2 TTPsAdversaries can establish persistent access to AWS environments by creating an IAM Roles Anywhere Trust Anchor using an unauthorized external Certificate Authority (CA) to sign forged client certificates.
AWS IAM OpenID Connect Provider Creation by Rare User
1 rule 3 TTPsAdversaries with administrative access to an AWS account may create rogue OpenID Connect (OIDC) Identity Providers to establish persistent, federated access that bypasses credential rotation and allows them to assume IAM roles using tokens from an attacker-controlled Identity Provider.
AWS Root Account Persistence via CreateLoginProfile
1 rule 2 TTPsAdversaries with temporary root access may invoke the CreateLoginProfile API without a username to establish persistent console password access for the AWS root principal.
Suspicious AWS IAM API Calls via Temporary Session Tokens
1 rule 2 TTPsThis detection rule identifies suspicious AWS IAM API operations performed using temporary session credentials (access keys starting with ASIA) that are not sourced from console logins, indicating potential credential theft, session hijacking, or abuse of privileged temporary credentials by an attacker for persistence, privilege escalation, or defense evasion within the AWS environment.
Detection of Unauthorized Amazon Bedrock Foundation Model Access Attempts
1 rule 1 TTPDetection of failed API calls attempting to enable Amazon Bedrock foundation model access, serving as a high-signal indicator for credential boundary-testing and potential LLMjacking.
AWS IAM Virtual MFA Device Registration Attempt with Session Token
1 rule 3 TTPsAdversaries are exploiting compromised temporary AWS session credentials (access keys starting with 'ASIA') to register or enable virtual MFA devices, establishing persistence and maintaining access to high-privilege accounts even after credential rotation or password resets.
AWS Lateral Movement via Kubernetes Service Account Identity Exploitation
4 TTPsAdversaries are exploiting Kubernetes service account tokens exchanged for AWS IAM credentials via AssumeRoleWithWebIdentity to conduct unauthorized reconnaissance, credential theft, and persistent access within AWS environments.
Abuse of AWS S3 SSE-C for Ransomware Extortion
1 rule 1 TTPAdversaries with compromised AWS credentials can abuse Server-Side Encryption with Customer-Provided Keys (SSE-C) to encrypt S3 objects with attacker-controlled keys, effectively holding organizational data for ransom.
AWS RDS Deletion Protection Disabled
1 rule 2 TTPsAdversaries with elevated IAM permissions may disable deletion protection on AWS RDS instances or clusters as a prerequisite for unauthorized data destruction.
Abuse of AWS KMS DeleteImportedKeyMaterial for Data Sabotage
1 rule 1 TTPAdversaries can perform immediate data destruction in AWS by invoking the DeleteImportedKeyMaterial API, rendering all data protected by external-origin (BYOK) keys inaccessible without a recovery window.
Detection of Unauthorized AWS Backup Recovery Point Deletion
1 rule 1 TTPUnauthorized deletion of AWS Backup recovery points via the DeleteRecoveryPoint API is an anti-recovery technique used by adversaries to prevent data restoration following destructive or ransomware attacks.
AWS RDS Database Snapshot Unauthorized External Sharing
1 rule 1 TTPAdversaries may exfiltrate sensitive data from AWS RDS by modifying snapshot attributes to share them with an external, attacker-controlled AWS account, enabling unauthorized offline access to the database content.
AWS ECR Repository or Registry Policy Granted Public Access
1 rule 1 TTPDetection of unauthorized configuration changes to AWS ECR policies that grant public access via wildcard principals, potentially leading to container image exfiltration or supply chain implantation.
AWS EC2 EBS Snapshot Exfiltration via ModifySnapshotAttribute
1 TTPAdversaries may exploit the ModifySnapshotAttribute API to share Amazon EBS snapshots with external accounts or the public, facilitating data exfiltration and unauthorized access to sensitive volume data.
AWS EC2 AMI Shared with Another Account
1 rule 1 TTP 4 IOCsAdversaries with existing AWS access may exfiltrate sensitive data by sharing Amazon Machine Images (AMIs) containing secrets, bash histories, or code artifacts with external, attacker-controlled AWS accounts, detectable via `ModifyImageAttribute` actions in AWS CloudTrail logs.
Detection of Anomalous AWS DynamoDB Scan Operations
3 TTPsThis detection brief identifies potential data exfiltration or unauthorized collection by monitoring for unusual AWS DynamoDB Scan operations performed by users or roles exhibiting non-typical behavior.
Abuse of AWS Systems Manager for Remote LOLBin Execution
1 rule 4 TTPsAdversaries are abusing the AWS Systems Manager SendCommand API to remotely execute commands on EC2 instances by leveraging legitimate system utilities (LOLBins) to bypass CloudTrail parameter redaction.
Detection of Anomalous Direct AWS Lambda Function Invocations
1 TTPThis threat brief details the risk of unauthorized or lateral movement via direct AWS Lambda function invocation by non-standard principals, highlighting detection methodologies for cloud environments.
AWS S3 Rapid Bucket Posture API Calls from a Single Principal
4 TTPsThis detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.
LLMjacking via Compromised AWS Long-Term IAM Credentials
1 rule 2 TTPsAdversaries are abusing stolen long-term AWS IAM access keys to perform unauthorized reconnaissance and high-cost model inference within Amazon Bedrock.
Detection of Unauthorized AWS WAF Rule Deletion
1 rule 1 TTPAdversaries may delete AWS WAF rules or rule groups via API to impair security boundaries and facilitate follow-on exploitation of web applications.
AWS SQS PurgeQueue Defense Evasion
1 rule 2 TTPsAdversaries may use the PurgeQueue action in AWS Simple Queue Service (SQS) to permanently delete all messages within a queue to disrupt operations, destroy forensic evidence, or evade detection.
Detection of Unauthorized AWS RDS Instance Restoration
1 rule 3 TTPsThreat actors with compromised AWS credentials may use RDS restoration operations to duplicate sensitive database environments, facilitating unauthorized data access, staging, and exfiltration while bypassing production monitoring controls.
AWS GuardDuty Member Account Manipulation
1 rule 1 TTPAdversaries manipulate Amazon GuardDuty member accounts within an AWS organization by using API calls such as `DisassociateFromAdministratorAccount`, `DeleteMembers`, `StopMonitoringMembers`, or `DeleteInvitations` to break centralized security visibility, enabling them to operate undetected in compromised member accounts.
Detection of Anomalous AWS IAM Long-Term Access Key Usage
2 TTPsThis brief describes a detection capability for identifying potentially unauthorized programmatic access by monitoring for successful AWS IAM long-term access key usage originating from previously unseen source IP addresses.
AWS S3 Bucket ACL Modification to Public Access by New Identity
1 rule 1 TTPDetection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.
Detection of Web Server Reconnaissance via Error Log Spikes
1 rule 3 TTPsThis brief covers the detection of automated reconnaissance activities, such as vulnerability scanning and fuzzing, which manifest as significant spikes in web server error logs.