FalconFriday — Detecting enumeration in AWS — 0xFF25 OrangeCon 25 Edition
ID: a2cf2904-0e1e-5f0c-a392-7ac462de0bfa
STIX ID: report--a2cf2904-0e1e-5f0c-a392-7ac462de0bfa
Feed Name: FalconForce
The post details how attackers can abuse AWS IAM Policy Simulator (via console and APIs) to enumerate and validate permissions—often automated with tools like dAWShund—and how defenders can detect this activity through CloudTrail footprints, distinctive List* pagination patterns, rare use of simulation APIs, and supplemental hunts for Credential Report and Access Analyzer events, accompanied by a newly released detection rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
