AWS Privilege Escalation Via User Compromise
Query
Detection:
- Group:
- ID: User Backdoored
RuleID: AWS.IAM.Backdoor.User.Keys
- ID: User Accessed
RuleID: AWS.CloudTrail.UserAccessKeyAuth
MatchCriteria:
field_name:
- GroupID: User Backdoored
Match: p_alert_context.ip_accessKeyId
- GroupID: User Accessed
Match: p_alert_context.ip_accessKeyId
Schedule:
RateMinutes: 1440
TimeoutMinutes: 10
LookbackWindowMinutes: 1800
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Panther group
AWS.CloudTrail.UserAccessKeyAuthwithin 1800m -
correlates · Panther group
AWS.IAM.Backdoor.User.Keyswithin 1800m