Product
Cross-Environment Secret Harvesting via Cloud APIs
1 TTPAdversaries are utilizing compromised credentials and stolen session tokens to perform rapid, automated secret harvesting across AWS, GCP, Azure, and Kubernetes environments from singular source IP addresses.
Detection of Unauthorized AWS Secrets Manager Credential Retrieval
1 rule 1 TTPAn adversary who has compromised an AWS service instance, such as EC2 or Lambda, may leverage assigned IAM roles to programmatically retrieve sensitive credentials from AWS Secrets Manager using the GetSecretValue API.
Shai-Hulud Malware Used in Supply Chain Attack via Compromised npm Packages
3 rules 7 TTPs 3 IOCsThe Shai-Hulud malware was used in a large-scale software supply-chain attack compromising hundreds of packages across open-source software ecosystems by compromising developer secrets and CI/CD pipelines.
AWS Secrets Manager Rapid Secrets Retrieval Attempts
2 rules 1 TTPCompromised AWS credentials may be used to rapidly retrieve multiple secrets from AWS Secrets Manager in order to escalate privileges or move laterally within the environment.
Multiple Cloud Secrets Accessed by Source Address
2 rules 1 TTPA single source IP accessing secret-management APIs across multiple cloud providers (AWS, GCP, Azure) and Kubernetes clusters within a short timeframe indicates credential theft or token replay for secret harvesting.
First Time Seen AWS Secret Value Accessed in Secrets Manager
2 rules 1 TTPThis rule detects the first time a specific user identity has programmatically retrieved a secret value from AWS Secrets Manager using the GetSecretValue action, which may indicate a compromised AWS service attempting to access secrets.