FalconFriday — Detecting enumeration in AWS — 0xFF25 OrangeCon 25 Edition
ID: 52706051-ed06-55c7-b341-8e809341032f
STIX ID: report--52706051-ed06-55c7-b341-8e809341032f
Feed Name: FalconForce
Threat Score
This FalconFriday blog explains how attackers can leverage the AWS IAM Policy Simulator (via console or the SimulatePrincipalPolicy/SimulateCustomPolicy APIs) and AWS-native tools (Credential Report, Access Analyzer) to enumerate permissions and find escalation paths, describes unique CloudTrail footprints left by such simulation activity, and provides detection guidance and KQL hunting queries to identify misuse and related reconnaissance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
