mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
19 lines
1017 B
YAML
19 lines
1017 B
YAML
name: AWS Credential Access
|
|
id: 4210b690-293f-411d-a9d8-bcfb2ea5fff9
|
|
version: 1
|
|
date: '2022-08-19'
|
|
author: Gowthamaraj Rajendran, Bhavin Patel, Splunk
|
|
description: Identify activity and techniques associated with accessing credential files from AWS resources, monitor unusual authentication related activities to the AWS Console and other services such as RDS.
|
|
narrative: Adversaries employ a variety of techniques to steal AWS Cloud credentials like account names, passwords and keys. Usage of legitimate keys will assist the attackers to gain access to other sensitive system and they can also mimic legitimate behaviour making them harder to be detected. Such activity may involve mulitple failed login to the console, new console logins and password reset activities.
|
|
references:
|
|
- https://attack.mitre.org/tactics/TA0006/
|
|
tags:
|
|
analytic_story: AWS Credential Access
|
|
category:
|
|
- Cloud Security
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|