Analytics BIOC
Informational
✕
A user logged in to the AWS console for the first time
A user logged in to the AWS console for the first time.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003) Lateral Movement (TA0008)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Credentials (T1098.001) Remote Services: Cloud Services (T1021.007)
Attacker's goals:
Evading detections by performing direct operations using the AWS console. Performing non-automatic operations easily.
Investigative actions:
Check if the identity is an AWS identity. Investigate which operations were performed by the identity.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
1 variation:
- A non-user identity logged in to the AWS console for the first time Medium (parent: Informational)