This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
AWS ConsoleLogin Failed Authentication
Original Source:
[Sigma source]
Title:
AWS ConsoleLogin Failed Authentication
Status:
experimental
Description:
Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
References:
-https://naikordian.github.io/blog/posts/brute-force-aws-console/
-https://help.fortinet.com/fsiem/Public_Resource_Access/7_2_1/rules/PH_RULE_AWS_Management_Console_Brute_Force_of_Root_User_Identity.htm
-https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/aws_login_failure/aws_cloudtrail_events.json
Author:
Ivan Saakov, Nasreddine Bencherchali
Date:
2025-10-19
modified:
None
Tags:
-'attack.credential-access'
-'attack.t1110'
Logsource:
product: aws
service: cloudtrail
Detection:
selection:
eventName
:
'ConsoleLogin'
errorMessage
:
'Failed authentication'
condition
:
selection
Falsepositives:
-Legitimate failed login attempts by authorized users. Investigate the source of repeated failed login attempts.
Level:
medium