Techniques
Sample rules
AWS IAM Password Recovery Requested
- source: elastic
- technicques:
- T1078
Description
Identifies AWS IAM password recovery requests. An adversary may attempt to gain unauthorized AWS access by abusing password recovery mechanisms.
Detection logic
event.dataset:aws.cloudtrail and event.provider:signin.amazonaws.com and event.action:PasswordRecoveryRequested and event.outcome:success