Analytics BIOC Informational

AWS IAM resource group deletion

An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Account Access Removal (T1531)
Attacker's goals:

An attacker may interrupt the availability of an account, this may revoke access to the account.

Investigative actions:

Check what members were affected by this action.

Test period:
N/A (single event)
Deduplication:
1 Day