Tag
high
advisory
AWS Lambda Function URL Created with Public Access
1 rule 2 TTPsAdversaries can establish persistent, internet-accessible footholds within AWS environments by configuring AWS Lambda function URLs with an authentication type of NONE, allowing unauthenticated invocation directly from the public internet for command and control, data exfiltration, or on-demand code execution.
AWS Lambda
cloud
aws
aws-lambda
threat-detection
persistence
defense-evasion
1r
2t
medium
advisory
AWS Lambda Function Invoked Cross-Account
1 TTPAdversaries leverage cross-account access to invoke AWS Lambda functions from a different account than the function owner, enabling code execution or data retrieval, which requires AWS Lambda data event logging to detect.
AWS Lambda
cloud
aws
aws-lambda
execution
cloud-security
1t