This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
AWS Successful Console Login Without MFA
Original Source:
[Sigma source]
Title:
AWS Successful Console Login Without MFA
Status:
experimental
Description:
Detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
References:
-https://securitylabs.datadoghq.com/cloud-security-atlas/vulnerabilities/iam-user-without-mfa/
-https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference-aws-console-sign-in-events.html
Author:
Thuya@Hacktilizer, Ivan Saakov
Date:
2025-10-18
modified:
2025-10-21
Tags:
-'attack.initial-access'
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1078.004'
Logsource:
product: aws
service: cloudtrail
Detection:
selection:
eventName
:
'ConsoleLogin'
additionalEventData.MFAUsed
:
'NO'
responseElements.ConsoleLogin
:
'Success'
condition
:
selection
Falsepositives:
-Unlikely
Level:
medium