AWSCloudTrail - IAM New Access Key Created for User

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects CreateAccessKey events where a principal creates new access keys, which may indicate persistence or privilege abuse if generated for another identity.

Attribute Value
Type Hunting Query
Solution Amazon Web Services
ID a2772445-9bb1-4176-9481-b262cb59118a
Severity Low
Tactics Persistence, PrivilegeEscalation
Techniques T1098, T1098.004
Required Connectors AWS
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AWSCloudTrail EventName == "CreateAccessKey"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Amazon Web Services