AWS Security Hub - Detect root user lacking MFA

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query detects AWS accounts where the root user does not have multi-factor authentication (MFA) enabled, using AWS Security Hub control IAM.9 findings. Lack of MFA on the root user increases the risk of unauthorized access and privilege abuse.

Attribute Value
Type Analytic Rule
Solution AWS Security Hub
ID 6b3b9b1d-0d5d-4d4a-9f0f-8d1e2c7a5f44
Severity High
Status Available
Kind Scheduled
Tactics PrivilegeEscalation, Persistence, CredentialAccess, DefenseEvasion
Techniques T1098, T1110, T1556.006
Required Connectors AWSSecurityHub
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AWSSecurityHubFindings ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to AWS Security Hub