Tag
medium
advisory
Detection of AWS SES Identity Verify-Use-Delete Abusive Pattern
1 rule 3 TTPsAdversaries with unauthorized access to AWS Simple Email Service (SES) credentials may verify an attacker-controlled identity, send phishing or spam emails, and promptly delete the identity to evade detection and attribution.
Simple Email Service +2
cloud
aws
ses
resource-development
defense-evasion
discovery
credential-abuse
1r
3t
updated
medium
advisory
Detection of Unauthorized AWS STS GetCallerIdentity Discovery
1 rule 2 TTPsAdversaries with compromised credentials may abuse the AWS STS GetCallerIdentity API to verify access and identify the current account context, serving as a primary indicator of initial cloud reconnaissance.
AWS Security Token Service
cloud
aws
cloudtrail
discovery
credential-abuse
1r
2t