Skip to content
Threat Feed

Tag

Resource-Development

8 briefs RSS
high advisory

Detection of AWS Route 53 Resolver Query Log Deletion

Adversaries may delete Amazon Route 53 Resolver Query Log configurations to evade detection by disabling DNS query and response logging for VPC-based resources.

Route 53 cloud aws defense-evasion log-auditing persistence resource-development
2r 3t
medium advisory

Abuse of AWS SES Account-Level Email Sending

Threat actors with compromised AWS credentials may enable account-level email sending in Amazon SES to restore suspended infrastructure for mass phishing campaigns.

AWS SES cloud aws resource-development ses
1r 1t
medium advisory

Detection of Anomalous AWS Service Quota Increases

Adversaries with compromised AWS credentials may request service quota increases to facilitate large-scale malicious operations, detectable by identifying rare identities invoking the RequestServiceQuotaIncrease API.

AWS Service Quotas cloud aws resource-development cloudtrail
1t
medium advisory

Unusual Attachment of AmazonSESFullAccess Policy in AWS

Threat actors may attach the AmazonSESFullAccess policy to IAM entities to establish phishing infrastructure and send emails using a victim organization's verified domain.

AWS IAM +1 persistence resource-development aws iam
1r 2t
medium advisory

Detection of AWS SES Identity Verify-Use-Delete Abusive Pattern

Adversaries with unauthorized access to AWS Simple Email Service (SES) credentials may verify an attacker-controlled identity, send phishing or spam emails, and promptly delete the identity to evade detection and attribution.

Simple Email Service +2 cloud aws ses resource-development defense-evasion discovery credential-abuse
1r 3t updated
low advisory

Anomalous Linux Compiler Activity Detection

Elastic has developed a machine learning detection rule to identify anomalous compiler activity on Linux systems, which can indicate unauthorized software deployment, ad-hoc changes, or privilege escalation attempts by adversaries.

endpoint linux machine-learning detection-rule resource-development defense-evasion privilege-escalation
3t
low advisory

AWS SNS Topic Created by Rare User

An AWS SNS topic was created by a user who does not typically perform this action, potentially indicating resource development for data exfiltration or other malicious activities.

Simple Notification Service cloud aws sns resource-development impact
2r 2t
high advisory

AWS Route 53 Domain Transferred to Another Account

An AWS Route 53 domain was transferred to another AWS account, potentially leading to unauthorized control over DNS records and traffic redirection for malicious purposes, such as phishing or establishing persistence.

Route 53 aws route53 domain-transfer persistence resource-development
2r 2t