Title:AWS User Login Profile Was Modified Status:test Description:Detects activity when someone is changing passwords on behalf of other users.
An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
References: -https://github.com/RhinoSecurityLabs/AWS-IAM-Privilege-Escalation Author: toffeebr33k Date: 2021-08-09 modified:2024-04-26 Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.t1098'
Logsource:
product: aws
service: cloudtrail
Detection: selection: eventSource:
'iam.amazonaws.com' eventName:
'UpdateLoginProfile' filter_main_user_identity: userIdentity.arn|fieldref:
'requestParameters.userName' condition:selection and not 1 of filter_main_* Falsepositives:
-Legitimate user account administration Level:high