logo

Managed Detection & Response for AWS

ID: 8c638382-deac-5268-a249-4c99378f7336

STIX ID: report--8c638382-deac-5268-a249-4c99378f7336

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2020-04-28

Date Updated: 2026-04-27

Author: Anthony Randazzo; Britton Manahan; Sam Lipton

...
...

Expel details a real-world AWS incident where attackers used stolen IAM access keys to enumerate S3, EC2, and RDS resources, add hundreds of Security Group ingress rules to expose services (including Postgres), create SSH key pairs and start an EC2 instance to gain command-line access; the post explains detection via CloudTrail and GuardDuty (with automated enrichment robots), investigative findings, containment steps (delete keys, remove SG rules, snapshot/rebuild instances), and recommendations to harden IAM and key management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.