Analytics BIOC
Low
✕
Unusual AWS user added to group
AWS user added to AWS group, possibly to elevate privileges and gain more access to resources.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Gain persistence and elevate privileges.
Investigative actions:
Check if the action was done using an automation service. Check if there are any other suspicious activities originated from the same machine/executing user.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Unusual AWS user added to group from a Kubernetes Pod Low