Techniques
Sample rules
AWS IAM User Addition to Group
- source: elastic
- technicques:
- T1098
Description
Identifies the addition of a user to a specified group in AWS Identity and Access Management (IAM).
Detection logic
event.dataset:aws.cloudtrail and event.provider:iam.amazonaws.com and event.action:AddUserToGroup and event.outcome:success