AWS User Login Profile Was Modified

 Original Source: [Sigma source]
Title: AWS User Login Profile Was Modified
Status: test
Description:Detects activity when someone is changing passwords on behalf of other users. An attacker with the "iam:UpdateLoginProfile" permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup.
References:
  -https://github.com/RhinoSecurityLabs/AWS-IAM-Privilege-Escalation
Author: toffeebr33k
Date: 2021-08-09
modified:2024-04-26
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1098'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'iam.amazonaws.com'
    eventName: 'UpdateLoginProfile'
  filter_main_user_identity:
    userIdentity.arn|fieldref: 'requestParameters.userName'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate user account administration
Level: high