- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Detect when the AmazonSESFullAccess
policy is attached to an AWS IAM role.
This rule allows you to monitor CloudTrail and detect if an attacker has attached the AWS managed policy AmazonSESFullAccess
to an AWS IAM role using the AttachRolePolicy
API call. An attacker with an objective of leveraging the AWS Simple Email Service (SES) may only attach a policy relating to SES to avoid detections relating to the AWS managed policy [AdministratorAccess
].
{{@userIdentity.session_name}}
should have made a {{@evt.name}}
API call.AmazonSESFullAccess
policy from the {{@requestParameters.roleName}}
role using the aws-cli
command detach-role-policy.{{@requestParameters.roleName}}
requires the AmazonSESFullAccess
policy to perform the intended function.