Files
splunk-security_content/playbooks/AWS_IAM_Account_Unlocking.yml
2026-05-19 11:12:49 -07:00

26 lines
786 B
YAML

name: AWS IAM Account Unlocking
id: f15a4db3-b157-4225-86ae-c36ab78b50f2
version: 2
creation_date: '2023-06-22'
modification_date: '2026-05-19'
author: Lou Stella, Splunk
type: Response
description: "Accepts user, to be enabled using AWS IAM connector. Enabling an account involves reattaching their login profile which will require setting a new password. This playbook produces a normalized observables output for each user. "
playbook: AWS_IAM_Account_Unlocking
how_to_implement: This input playbook requires the AWS IAM connector to be configured.
references: []
app_list:
- AWS IAM
platform_tags:
- user
- aws_iam
- D3-RUAA
- enable_account
playbook_type: Input
vpe_type: Modern
playbook_fields: []
product:
- Splunk SOAR
defend_technique_id:
- D3-RUAA