logo

Threat Hunting AWS CloudTrail with Microsoft Sentinel: Part 4

ID: ca220738-a08d-560a-b0de-ebd93f5e89f0

STIX ID: report--ca220738-a08d-560a-b0de-ebd93f5e89f0

Feed Name: Binary Defense Blog

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This report demonstrates adversary emulation in AWS using Atomic Red Team to simulate IAM-focused actions (CreateUser, CreateAccessKey, CreateGroup) and shows how to hunt and detect these behaviors in Microsoft Sentinel via KQL over CloudTrail logs. It provides step-by-step execution and corresponding detection queries for suspicious source IPs, user agents (e.g., Kali), and admin actions (notably by user “Jacko”), culminating in a consolidated hunt for IAM user creation, access key issuance, and group creation. The guidance concludes with SOC-focused recommendations to alert on new IAM users, access key creation, and group/policy changes to reduce false positives and enhance cloud monitoring efficacy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.