Tag
Okta Policy Rule Modification or Deletion
2 rules 1 TTPAn Okta policy rule was modified or deleted, potentially weakening security controls.
S3Browser IAM Policy Creation with Default Bucket Name
2 rules 3 TTPsAn AWS IAM policy is created by the S3Browser utility with the default S3 bucket name placeholder, potentially indicating unauthorized access or misconfiguration.
AWS Policy Created Allowing All Resources
2 rules 1 TTPAn AWS IAM policy version was created that allows all actions on all resources, potentially leading to privilege escalation or unauthorized access.
Okta Policy Modification or Deletion Detected
2 rules 1 TTPAn Okta policy was modified or deleted, potentially indicating unauthorized changes to security configurations within the Okta identity management platform by a malicious actor or insider.
Malicious Use of Microsoft Intune Device Management Configuration Policies
2 rules 3 TTPsAttackers can abuse Microsoft Intune device management configuration policies, typically used for legitimate remote device management, to disable defenses and evade detection on managed devices.
AWS IAM Policy Deletion Detection
2 rules 1 TTPDetection of AWS IAM policy deletion events, which could indicate malicious activity by a compromised account or insider threat.
AWS IAM Default Policy Version Modification
2 rules 1 TTPAn adversary modifies the default version of an AWS IAM policy, potentially downgrading security or disrupting access control.