<  Back to rules search

AWS IAM user escalating privileges

guardduty

Classification:

attack

Tactic:

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when an AWS IAM user is attempting to escalate permissions.

Strategy

This rule lets you monitor this GuardDuty integration finding:

Triage and response

  1. Determine which user triggered the signal. This can be found in the signal.
  2. Determine if the user’s credentials are compromised.
  3. If the user’s credentials are compromised:
  • Review the AWS [documentation][3] on remediating compromised AWS credentials.