Analytics BIOC Informational

An identity created or updated password for an IAM user

An identity created or updated an AWS console password for an IAM user.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Credentials (T1098.001)
Attacker's goals:

Escalate privileges, maintain persistence in cloud environments.

Investigative actions:

Verify whether the identity should be making this action. Examine what additional API calls were made by the identity.

Test period:
N/A (single event)
Deduplication:
5 Days
1 variation:
  • A suspicious identity created or updated password for an IAM user Low (parent: Informational)