LoFP LoFP / t1580

t1580

TitleTags
administrators listing buckets, it may be necessary to filter out users who commonly conduct this activity.
administrators or automated systems may legitimately perform multiple `describe` and `list` api calls in a short time frame. verify the user identity and the purpose of the api calls to determine if the behavior is expected.
it is possible to start this detection will need to be tuned by source ip or user. in addition, change the count values to an upper threshold to restrict false positives.
known or internal account ids or automation
legitimate use of the `describeinstances` api call by an aws resource that requires information about instances in multiple regions.
scheduled tasks or scripts that require information about instances in multiple regions.