Analytics BIOC Low

AWS Lambda Cross-Account sensitive permissions configured

A cloud identity has granted external AWS account sensitive permissions to a Lambda function.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003) Account Manipulation (T1098)
Attacker's goals:

Obtaining persistency by using a Lambda function in the target's environment as a backdoor.

Investigative actions:

Investigate any unusual activity originating from the suspected identity. Investigate any unusual Lambda functions related operations originating from the allowed added accounts. Validate the legitimacy of the AWS accounts that were allowed external access.

Test period:
N/A (single event)
Deduplication:
5 Days
3 variations:
  • AWS Lambda public sensitive permissions configured Medium (parent: Low)
  • AWS Lambda public permissions configured Low
  • AWS Lambda Cross-Account permissions configured Informational (parent: Low)