Skip to content
Discussion options

You must be logged in to vote

The problem was in Sigma rule "AWS User Login Profile Was Modified" - it has some errors.

Details

title: AWS User Login Profile Was Modified
id: 055fb148-60f8-462d-ad16-26926ce050f1
status: test
description: |
Detects activity when someone is changing passwords on behalf of other users.
An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
references:
- https://github.com/RhinoSecurityLabs/AWS-IAM-Privilege-Escalation
author: toffeebr33k
date: 2021-08-09
modified: 2024-04-26
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1098
logsource:
produc…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by Zer0-cyber-web
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
3.0
Labels
None yet
1 participant