name: AWS Successful Single-Factor Authentication id: a520b1fe-cc9e-4f56-b762-18354594c52f version: 1 date: '2022-10-04' author: Bhavin Patel, Splunk type: TTP datamodel: - Endpoint description: The following analytic identifies a successful Console Login authentication event against an AWS IAM user for an account without Multi-Factor Authentication enabled. This could be evidence of a misconfiguration, a policy violation or an account take over attempt that should be investigated search: '`cloudtrail` eventName= ConsoleLogin errorCode=success "additionalEventData.MFAUsed"=No | stats count min(_time) as firstTime max(_time) as lastTime by src eventName eventSource aws_account_id errorCode additionalEventData.MFAUsed userAgent eventID awsRegion user_name userIdentity.arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_successful_single_factor_authentication_filter`' how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search requires AWS Cloudtrail logs. known_false_positives: It is possible that some accounts do not have MFA enabled for the AWS account however its agaisnt the best practices of securing AWS. references: - https://attack.mitre.org/techniques/T1621/ - https://attack.mitre.org/techniques/T1078/004/ - https://aws.amazon.com/what-is/mfa/ tags: analytic_story: - AWS Identity and Access Management Account Takeover asset_type: AWS Account cis20: - CIS 3 - CIS 5 - CIS 16 confidence: 80 context: - Source:Cloud Data dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/aws_login_sfa/cloudtrail.json impact: 80 kill_chain_phases: - Exploitation message: User $user_name$ has successfully logged into an AWS Console without Multi-Factor Authentication from $src$ mitre_attack_id: - T1586 - T1586.003 - T1078 - T1078.004 nist: - DE.CM observable: - name: user_name type: User role: - Victim - name: src type: IP Address role: - Attacker product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - src - eventName - eventSource - aws_account_id - errorCode - additionalEventData.MFAUsed - userAgent - eventID - awsRegion - user_name - userIdentity.arn risk_score: 64 security_domain: threat