Analytics BIOC Informational

An identity attached an administrative policy to an IAM user or role

An identity attached an administrative policy to an IAM user or role.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Roles (T1098.003)
Attacker's goals:

Escalate privileges in cloud environments.

Investigative actions:

Confirm whether this activity was intentional. Check for other API calls that were executed by the identity. Look for any suspicious behavior from the IAM user or role to whom the administrative policy was attached.

Test period:
N/A (single event)
Deduplication:
5 Days
3 variations:
  • An identity attached an administrative policy to itself Medium (parent: Informational)
  • An identity failed to attach an administrative policy to an IAM user or role Medium (parent: Informational)
  • A suspicious identity attached an administrative policy to an IAM user/role Low (parent: Informational)