Files
splunk-security_content/stories/aws_credential_access.yml
patel-bhavin d1c0d94fd2 story file
2022-08-09 16:02:19 -07:00

19 lines
1017 B
YAML

name: AWS Credential Access
id: 4210b690-293f-411d-a9d8-bcfb2ea5fff9
version: 1
date: '2022-08-19'
author: Gowthamaraj Rajendran, Bhavin Patel, Splunk
description: Identify activity and techniques associated with accessing credential files from AWS resources, monitor unusual authentication related activities to the AWS Console and other services such as RDS.
narrative: Adversaries employ a variety of techniques to steal AWS Cloud credentials like account names, passwords and keys. Usage of legitimate keys will assist the attackers to gain access to other sensitive system and they can also mimic legitimate behaviour making them harder to be detected. Such activity may involve mulitple failed login to the console, new console logins and password reset activities.
references:
- https://attack.mitre.org/tactics/TA0006/
tags:
analytic_story: AWS Credential Access
category:
- Cloud Security
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Security Monitoring