AWS IAM User Changing Sensitive Configurations
Security Monitoring is now available Security Monitoring is now available
<  Back to rules search

AWS IAM User Changing Sensitive Configurations

guardduty

Classification:

attack

Tactic:

Technique:

Set up the guardduty integration.

Overview

Goal

Detect when an AWS IAM user is changing sensitive configurations and has no prior history of invoking these APIs.

Strategy

This rule lets you monitor these GuardDuty integration findings:

Triage & Response

  1. Determine which user triggered the signal. This can be found in the signal.
  2. Determine if the user’s credentials are compromised.
  3. If the user’s credentials are compromised:
    • Review the AWS documentation on remediating compromised AWS credentials.