AWS User Login Profile Was Modified
Description
Detects activity when someone is changing passwords on behalf of other users. An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
Query · sigma
selection: eventSource: iam.amazonaws.com eventName: UpdateLoginProfile filter_main_user_identity: userIdentity.arn|fieldref: requestParameters.userName condition: selection and not 1 of filter_main_*
Known false positives
- Legitimate user account administration