ChecklistCONSTRUCTEDUntestedMembers

First 15 minutes: an AWS access key used from somewhere new

GuardDuty or CloudTrail shows a key making calls from an unfamiliar address, or making calls it has never made. Find what it did, stop it without destroying the history, and look for the persistence that outlives the key.

high severityInitial AccessT1078.004T1098.001T1136.003T1685.002

The clock starts when

GuardDuty or a CloudTrail-based alert shows an access key used from an unfamiliar address, country or user agent, or used for API calls it does not normally make.

  1. minutes 0 to 5Identify the key and what it did3 lines
  2. minutes 5 to 10Stop it, keep the history3 lines
  3. minutes 10 to 15Scope cost and data3 lines

sources

  1. AWS re:Post: what to do if you notice unauthorized activity in your AWS account · primary
  2. AWS Docs: managing access keys for IAM users
  3. AWS Docs: revoking IAM role temporary security credentials
  4. AWS CloudTrail user guide

Tags: first-15 · aws · cloud · iam · cloudtrail · access-keys · T1078.004 · T1098.001