Analytics BIOC Informational

A user logged in to the AWS console for the first time

A user logged in to the AWS console for the first time.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003) Lateral Movement (TA0008)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Credentials (T1098.001) Remote Services: Cloud Services (T1021.007)
Attacker's goals:

Evading detections by performing direct operations using the AWS console. Performing non-automatic operations easily.

Investigative actions:

Check if the identity is an AWS identity. Investigate which operations were performed by the identity.

Test period:
N/A (single event)
Deduplication:
5 Days
1 variation:
  • A non-user identity logged in to the AWS console for the first time Medium (parent: Informational)