← Back to Explore
sigmamediumHunting
AWS Root Credentials
Detects AWS root account usage
Detection Query
selection_usertype:
userIdentity.type: Root
selection_eventtype:
eventType: AwsServiceEvent
condition: selection_usertype and not selection_eventtype
Author
vitaliy0x1
Created
2020-01-21
Data Sources
awscloudtrail
Platforms
aws
Tags
attack.privilege-escalationattack.defense-evasionattack.initial-accessattack.persistenceattack.t1078.004
Raw Content
title: AWS Root Credentials
id: 8ad1600d-e9dc-4251-b0ee-a65268f29add
status: test
description: Detects AWS root account usage
references:
- https://docs.aws.amazon.com/IAM/latest/UserGuide/id_root-user.html
author: vitaliy0x1
date: 2020-01-21
modified: 2022-10-09
tags:
- attack.privilege-escalation
- attack.defense-evasion
- attack.initial-access
- attack.persistence
- attack.t1078.004
logsource:
product: aws
service: cloudtrail
detection:
selection_usertype:
userIdentity.type: Root
selection_eventtype:
eventType: AwsServiceEvent
condition: selection_usertype and not selection_eventtype
falsepositives:
- AWS Tasks That Require AWS Account Root User Credentials https://docs.aws.amazon.com/general/latest/gr/aws_tasks-that-require-root.html
level: medium