Title:
AWS IAM Backdoor Users Keys
Status:
test
Description:Detects AWS API key creation for a user by another user.
Backdoored users can be used to obtain persistence in the AWS environment.
Also with this alert, you can detect a flow of AWS keys in your org.
References:
-https://github.com/RhinoSecurityLabs/pacu/blob/866376cd711666c775bbfcde0524c817f2c5b181/pacu/modules/iam__backdoor_users_keys/main.py
-https://github.com/SigmaHQ/sigma/issues/6223
Author: faloker
Date: 2020-02-12
modified:2026-08-14
Tags:
- -'attack.persistence'
- -'attack.privilege-escalation'
- -'attack.t1098'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection:
eventSource:
'iam.amazonaws.com'
eventName:
'CreateAccessKey'
filter_main_same_user:
userIdentity.arn|fieldref|contains:
'responseElements.accessKey.userName'
condition:
selection and not 1 of filter_main_*
Falsepositives:
-Adding user keys to their own accounts (the filter cannot cover all possible variants of user naming)
-AWS API keys legitimate exchange workflows
Level:
medium