Analytics BIOC Informational

AWS console login without MFA

An identity logged in to the AWS console without MFA.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003) Credential Access (TA0006)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Credentials (T1098.001) Multi-Factor Authentication Request Generation (T1621)
Attacker's goals:

Bypassing multifactor authentication controls to gain unauthorized access to the cloud environment.

Investigative actions:

Determine why MFA was not enforced and whether MFA was ever enabled. Track any subsequent activity performed by the identity after the login to identify potential misuse.

Test period:
N/A (single event)
Deduplication:
5 Days