Cloudtrail SecretsManager secret retrieved from AWS CloudShell environment

Esta página aún no está disponible en español. Estamos trabajando en su traducción.
Si tienes alguna pregunta o comentario sobre nuestro actual proyecto de traducción, no dudes en ponerte en contacto con nosotros.

Goal

Detect when an AWS secret is retrieved from an AWS CloudShell environment.

Strategy

Monitor CloudTrail and detect when an AWS secret is retrieved from an AWS CloudShell environment. The threat group LUCR-3 uses AWS CloudShell in the AWS management console to carry out activities that require direct interaction with the AWS API, such as the retrieval of secrets.

Triage and response

  1. Determine if {{@userIdentity.arn}} should have carried out this operation.
  2. If the API calls were not made by the user:
  • Rotate user credentials.
  • Rotate the secrets retrieved by the identity, if feasible.
  • Determine what other API calls were made by the user.
  • Begin your organization’s incident response process and investigate.