<  Back to rules search

AWS IAM user requests from malicious IP

guardduty

Classification:

attack

Tactic:

Technique:

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect when an AWS IAM user makes API requests from a malicious IP.

Strategy

This rule lets you monitor these GuardDuty integration findings:

Triage and response

  1. Determine which user triggered the signal. This can be found in the signal.
  2. Determine if the user’s credentials are compromised.
  3. If the user’s credentials are compromised:
  • Review the AWS documentation on remediating compromised AWS credentials.

Changelog

  • 1 November 2022 - Updated links.