{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/aws-service-quotas/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS Service Quotas"],"_cs_severities":["medium"],"_cs_tags":["cloud","aws","resource-development","cloudtrail"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries who obtain AWS credentials often perform resource development as a prerequisite for larger campaigns. By requesting AWS Service Quota increases, attackers can bypass default account limits that are intended to prevent runaway resource consumption. Increasing these limits allows for the deployment of industrial-scale infrastructure for activities such as cryptomining, DDoS amplification, high-volume phishing through Amazon SES, or large-scale credential stuffing using Lambda.\u003c/p\u003e\n\u003cp\u003eDefenders should monitor the AWS Service Quotas API for the 'RequestServiceQuotaIncrease' action, specifically focusing on identities that have no recent history (within a 7-day window) of performing such requests. Because legitimate cloud infrastructure teams also perform these tasks, filtering by common Infrastructure-as-Code (IaC) toolsets like Terraform, Pulumi, or Ansible is critical to reduce false positives.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of service quotas enables attackers to scale malicious operations beyond the organization's expected capacity. This can lead to significant financial costs due to unauthorized resource usage, increased exposure to downstream abuse reports for phishing, or the compromise of internal data through high-bandwidth exfiltration channels.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should implement monitoring for rare AWS Service Quota increase requests to identify potential malicious infrastructure preparation.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy detection logic to monitor 'RequestServiceQuotaIncrease' events in AWS CloudTrail for identities without a 7-day history of this API call.\u003c/li\u003e\n\u003cli\u003eFilter out service principals or IAM roles used by known IaC tools (e.g., Terraform, Pulumi, Ansible) to minimize noise.\u003c/li\u003e\n\u003cli\u003eInvestigate triggered alerts by cross-referencing the requesting identity with recent activity in the affected services (EC2, Lambda, SES).\u003c/li\u003e\n\u003cli\u003eUse AWS Service Control Policies (SCPs) to restrict 'servicequotas:RequestServiceQuotaIncrease' to authorized cloud-operations roles only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T10:42:30Z","date_published":"2026-09-07T10:42:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-quota-increase/","summary":"Adversaries with compromised AWS credentials may request service quota increases to facilitate large-scale malicious operations, detectable by identifying rare identities invoking the RequestServiceQuotaIncrease API.","title":"Detection of Anomalous AWS Service Quota Increases","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-quota-increase/"}],"language":"en","title":"CraftedSignal Threat Feed - AWS Service Quotas","version":"https://jsonfeed.org/version/1.1"}