Threat Hunting AWS CloudTrail with Sentinel: Part 3
ID: 803fddac-9137-5263-9f7a-324dd3ec4e96
STIX ID: report--803fddac-9137-5263-9f7a-324dd3ec4e96
Feed Name: Binary Defense Blog
This post details a simulated adversary workflow in AWS—creating secondary IAM access keys and abusing STS AssumeRole with Pacu for backdoor access and privilege escalation—and demonstrates how to detect these behaviors in Microsoft Sentinel using KQL over CloudTrail logs (e.g., CreateAccessKey, ListAccessKeys, GetRole, AssumeRole). It emphasizes practical hunting techniques for enumeration patterns, suspicious user agents (such as Kali), and role modifications so SOC teams can build tailored detections and baselines for cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
