Analytics BIOC
Informational
✕
AWS console login without MFA
An identity logged in to the AWS console without MFA.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003) Credential Access (TA0006)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Credentials (T1098.001) Multi-Factor Authentication Request Generation (T1621)
Attacker's goals:
Bypassing multifactor authentication controls to gain unauthorized access to the cloud environment.
Investigative actions:
Determine why MFA was not enforced and whether MFA was ever enabled. Track any subsequent activity performed by the identity after the login to identify potential misuse.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days