Product
AWS IAM User Console Login Without MFA
1 rule 1 TTPThis brief identifies successful logins to the AWS Management Console by standard IAM users without Multi-Factor Authentication (MFA). It focuses on the first observed occurrence within a 7-day history window for each user. An adversary who obtains a user's password can gain access if MFA is not enforced, representing a significant initial access vector. This event signals a critical posture gap that allows adversaries to achieve initial access using compromised credentials, leading to potential privilege escalation, data exfiltration, or resource deployment.
AWS Sensitive IAM Operations Performed via CloudShell
1 rule 4 TTPsAttackers can leverage a compromised AWS console session to perform sensitive AWS IAM operations via AWS CloudShell, establishing persistence or escalating privileges, which can be detected by monitoring CloudTrail logs for specific user agent strings and high-risk IAM actions.
AWS IAM User Console Login from Multiple Geolocations
2 TTPsAdversaries leverage adversary-in-the-middle (AiTM) phishing and session theft to compromise AWS IAM user credentials, leading to concurrent successful AWS Management Console logins from multiple distinct geographic locations, indicating account compromise and enabling unauthorized access to cloud resources despite MFA.
AWS Federated User Console Login without MFA Enforcement
2 rules 1 TTPDetection of successful AWS Management Console logins by federated users, which pose a security risk due to potential lack of enforced MFA as CloudTrail does not reliably record MFA status for federated users.
AWS Console Login by User from New Region
2 rules 1 TTPAn AWS account may be compromised if a user logs into the AWS console from a geographic region they have never accessed before, potentially indicating unauthorized access or account takeover.
AWS Console Login by User from New City
2 rules 1 TTPDetection of AWS console logins by a user from a previously unseen city, potentially indicating compromised credentials or account takeover.
Successful AWS Console Login Without MFA
2 rules 1 TTPSuccessful AWS console logins without multi-factor authentication can indicate compromised credentials, misconfigured security settings, or unauthorized access attempts.
AWS Management Console Failed Login Attempts
2 rules 2 TTPsDetection of repeated failed login attempts to the AWS Management Console, potentially indicating brute-force or credential access attempts by threat actors aiming to compromise AWS accounts.
AWS Login Profile Creation Followed by Console Login
2 rules 2 TTPsDetection of an AWS user creating a login profile for another user, followed by a console login from the same source IP, potentially indicating privilege escalation.
AWS Console Login from New City
2 rules 1 TTPA user logging into the AWS console from a previously unseen city could indicate compromised credentials or an insider threat.
AWS Console Login Failed During MFA Challenge
2 rules 2 TTPsDetection of failed AWS console login attempts despite successful MFA usage, indicating potential account compromise attempts.
AWS Console Login by User from New Country
2 rules 1 TTPThis detection identifies AWS console logins by a user originating from a country not previously associated with that user, potentially indicating account compromise.
AWS Account Console Login Without MFA
2 rules 2 TTPsDetection of successful AWS console login events without multi-factor authentication (MFA) enabled, potentially indicating misconfiguration, policy violation, or account compromise.
AWS Management Console Root Login Detected
2 rules 2 TTPsDetection of a successful AWS Management Console login by the Root user, which is an original identity with unrestricted privileges, indicates a potential security breach requiring immediate investigation.
AWS Management Console Brute Force of Root User Identity
2 rules 1 TTPDetection of a high number of failed login attempts to the AWS Management Console targeting the root user, which can indicate a brute-force attack to gain complete access to the AWS account.
AWS IAM Operations via Compromised CloudShell
2 rules 4 TTPsCompromised AWS console sessions can lead to attackers performing sensitive IAM operations via CloudShell to establish persistence or escalate privileges.