Analytics BIOC Informational

IAM User added to an IAM group

An IAM user was added to an IAM group.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Privilege Escalation (TA0004) Persistence (TA0003)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Account Manipulation: Additional Cloud Roles (T1098.003)
Attacker's goals:

Add a user to a group to establish persistence or escalate privileges within a cloud account.

Investigative actions:

Identify the identity that executed the API call. Determine which IAM user was added to the group. Evaluate the group's permissions to determine their applicability to the IAM user.

Test period:
N/A (single event)
Deduplication:
1 Day