Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer
ID: 1f837038-77c9-5840-9bfd-99ca2ef4da8f
STIX ID: report--1f837038-77c9-5840-9bfd-99ca2ef4da8f
Feed Name: Datadog Security Labs
Datadog Security Research details how attackers could quietly enumerate AWS resources by leveraging Resource Explorer’s ListResources API—which was previously a data event not logged to CloudTrail by default—and reports that AWS reclassified it as a management event on July 15, 2025 to ensure default logging. The post outlines mitigations and detections, including using SCPs to disable Resource Explorer if unused and alerting on CreateIndex/ListResources (with emphasis on long‑lived access keys), and includes a timeline and AWS Health notice about the change.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
