Skip to content
Threat Feed

Product

AWS KMS

7 briefs RSS
medium advisory

Detection of SDK-Based AWS Control Plane Discovery from Suspicious Processes

This detection monitors for processes executing from temporary or user-writable directories that perform DNS queries to AWS management endpoints, a pattern frequently utilized by post-exploitation tools to bypass CLI-based security controls.

AWS IAM +5 cloud-security discovery aws credential-theft detection-engineering
2t
medium advisory

Abuse of AWS KMS DeleteImportedKeyMaterial for Data Sabotage

Adversaries can perform immediate data destruction in AWS by invoking the DeleteImportedKeyMaterial API, rendering all data protected by external-origin (BYOK) keys inaccessible without a recovery window.

AWS KMS cloud aws kms impact sabotage
1r 1t
medium advisory

AWS KMS Customer Managed Key Lifecycle Manipulation

Adversaries may disable or schedule the deletion of AWS KMS keys to sabotage business operations, render encrypted data unrecoverable, and obstruct forensic investigation or incident response efforts.

AWS Key Management Service +1 impact cloud-security aws-kms incident-response
1r 1t updated
low advisory

AWS CLI Discovery from Single Resource

An Elastic detection rule identifies when a single AWS identity, using the AWS CLI, performs more than five distinct read-only discovery API calls (such as Describe*, List*, Get*, and Generate*) across various AWS services within a 10-second window, indicating reconnaissance by an adversary using compromised credentials or an exploited EC2 instance to map the AWS infrastructure for potential targets and further exploitation.

AWS +13 cloud discovery reconnaissance cli
2t
high threat

AWS Discovery API Calls from VPN ASN for the First Time by Identity

This threat detection rule identifies initial reconnaissance activities within AWS by flagging an IAM principal's first-time invocation of sensitive discovery APIs, such as GetCallerIdentity, ListUsers, ListBuckets, and DescribeInstances, when the originating IP address is associated with consumer VPNs, high-usage hosting providers, or networks linked to threat groups like TeamPCP, indicating an attacker performing enumeration of cloud resources from a suspicious network origin.

AWS CloudTrail +12 TeamPCP aws-cloudtrail iam discovery cloud identity threat-detection
1r 2t 22i updated
high advisory

AWS Bedrock API Key Phantom User Activity Outside Bedrock

An Amazon Bedrock API key phantom user (IAM user starting with 'BedrockAPIKey-*') performing non-Bedrock API calls, such as to IAM, STS, EC2, VPC, or KMS, indicates credential misuse and realized privilege escalation by an attacker using added standard IAM access keys for reconnaissance or lateral movement beyond the intended Bedrock authentication boundary.

AWS Bedrock +5 cloud-security privilege-escalation aws bedrock iam
1r 1t
medium advisory

AWS KMS Imported Key Material Deleted

Adversaries leverage the `DeleteImportedKeyMaterial` API call against AWS KMS customer managed keys (CMKs) with external material, instantly rendering encrypted data inaccessible with no recovery window, facilitating cloud ransomware or data destruction attacks.

AWS KMS cloud aws kms data-destruction ransomware
1r 1t