Product
medium
advisory
Unusual Attachment of AmazonSESFullAccess Policy in AWS
1 rule 2 TTPsThreat actors may attach the AmazonSESFullAccess policy to IAM entities to establish phishing infrastructure and send emails using a victim organization's verified domain.
AWS IAM +1
persistence
resource-development
aws
iam
1r
2t
low
advisory
AWS CLI Discovery from Single Resource
2 TTPsAn Elastic detection rule identifies when a single AWS identity, using the AWS CLI, performs more than five distinct read-only discovery API calls (such as Describe*, List*, Get*, and Generate*) across various AWS services within a 10-second window, indicating reconnaissance by an adversary using compromised credentials or an exploited EC2 instance to map the AWS infrastructure for potential targets and further exploitation.
AWS +13
cloud
discovery
reconnaissance
cli
2t