Techniques
Sample rules
AWS IAM Backdoor Users Keys
- source: sigma
- technicques:
- t1098
Description
Detects AWS API key creation for a user by another user. Backdoored users can be used to obtain persistence in the AWS environment. Also with this alert, you can detect a flow of AWS keys in your org.
Detection logic
condition: selection and not 1 of filter_main_*
filter_main_same_user:
userIdentity.arn|fieldref|contains: responseElements.accessKey.userName
selection:
eventName: CreateAccessKey
eventSource: iam.amazonaws.com