Analytics BIOC
Informational
✕
An identity created or updated password for an IAM user
An identity created or updated an AWS console password for an IAM user.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Credentials (T1098.001)
Attacker's goals:
Escalate privileges, maintain persistence in cloud environments.
Investigative actions:
Verify whether the identity should be making this action. Examine what additional API calls were made by the identity.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
1 variation:
- A suspicious identity created or updated password for an IAM user Low (parent: Informational)