Managed Detection & Response for AWS
ID: 8c638382-deac-5268-a249-4c99378f7336
STIX ID: report--8c638382-deac-5268-a249-4c99378f7336
Feed Name: Expel Blog
Date Published: 2020-04-28
Date Updated: 2026-04-27
Author: Anthony Randazzo; Britton Manahan; Sam Lipton
Expel details a real-world AWS incident where attackers used stolen IAM access keys to enumerate S3, EC2, and RDS resources, add hundreds of Security Group ingress rules to expose services (including Postgres), create SSH key pairs and start an EC2 instance to gain command-line access; the post explains detection via CloudTrail and GuardDuty (with automated enrichment robots), investigative findings, containment steps (delete keys, remove SG rules, snapshot/rebuild instances), and recommendations to harden IAM and key management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
