logo

Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer

ID: 1f837038-77c9-5840-9bfd-99ca2ef4da8f

STIX ID: report--1f837038-77c9-5840-9bfd-99ca2ef4da8f

Feed Name: Datadog Security Labs

Date Published: 2025-08-19

Date Updated: 2026-04-27

...
...

Datadog Security Research details how attackers could quietly enumerate AWS resources by leveraging Resource Explorer’s ListResources API—which was previously a data event not logged to CloudTrail by default—and reports that AWS reclassified it as a management event on July 15, 2025 to ensure default logging. The post outlines mitigations and detections, including using SCPs to disable Resource Explorer if unused and alerting on CreateIndex/ListResources (with emphasis on long‑lived access keys), and includes a timeline and AWS Health notice about the change.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.