cloudwatch or cloudtrail for lambda passrole attack

0

We have one aws user has passrole, lambda invoke and create inline policy, we suspect this user use lambda script to passrole and attach awsadminaccess policy to his account, how can we identify this? through cloudwatch or cloudtrail? if through cloudtrail, how would we know the lamda script he invoke is malicious and how to track role change for this IAM account giving date range? thanks

질문됨 2년 전258회 조회
2개 답변
0

For sensitive questions, I'd reach out to AWS Support for help as well.

For AWS Management API calls including IAM Changes such as:

In Cloudtrail, you can filter by dates and search by Events as well. For checking the Lambda, you can check Invocation of the Lambda (Lambda being run as well).

There are some AWS Services that offer checks like that such as AWS Config: https://docs.aws.amazon.com/config/latest/developerguide/iam-policy-no-statements-with-admin-access.html, but you may want to evaluate the cost of those services as well.

For information about to do with suspected compromise, read here: https://aws.amazon.com/premiumsupport/knowledge-center/potential-account-compromise/.

jsonc
답변함 2년 전
0

Hi, I checked the cloudtrail, I define the time range, then i search event name: attachrolepolicy.

i want to further restricted by user or other criteria, how to do? it only allow me to search one criterial for example Event name

답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠