AWSCloudTrail - Creation of Access Key for IAM User

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects creation of a new IAM access key on an existing user account, which could be used to establish persistence. This action should be validated by the AWS account administrator. Reference: https://stratus-red-team.cloud/attack-techniques/AWS/aws.persistence.iam-backdoor-user/

Attribute Value
Type Analytic Rule
Solution Amazon Web Services
ID 9a6554e6-63d9-4f94-9b32-64d1d40628f2
Severity Medium
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1098.001
Required Connectors AWS
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AWSCloudTrail EventName == "CreateAccessKey"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Amazon Web Services