AWS Successful Console Login Without MFA

 Original Source: [Sigma source]
Title: AWS Successful Console Login Without MFA
Status: experimental
Description:Detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
References:
  -https://securitylabs.datadoghq.com/cloud-security-atlas/vulnerabilities/iam-user-without-mfa/
  -https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference-aws-console-sign-in-events.html
Author: Thuya@Hacktilizer, Ivan Saakov
Date: 2025-10-18
modified:2025-10-21
Tags:
  • -'attack.initial-access'
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1078.004'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventName: 'ConsoleLogin'
    additionalEventData.MFAUsed: 'NO'
    responseElements.ConsoleLogin: 'Success'
  condition:selection
Falsepositives:
  -Unlikely
Level: medium