How to Detect Suspicious AWS IAM Activity with Microsoft Sentinel

Create Sentinel detections for suspicious AWS IAM changes, access keys, privilege escalation, trust relationships, and logging manipulation.

Dikshant Lather
1 min read ·
How to Detect Suspicious AWS IAM Activity with Microsoft Sentinel

Create Sentinel detections for suspicious AWS IAM behavior by modeling identity attack paths rather than isolated API calls.

Attack Path

Compromised Identity
 -> Credential Creation
 -> Privilege Escalation
 -> Persistence
 -> Trust Modification
 -> Defense Evasion

High-Value Detections

Monitor:

  • Unexpected access-key creation
  • IAM policy changes
  • Trust-policy changes
  • Root activity
  • Logging changes

For each event correlate actor, target, source IP, account, time, resource, and change-ticket context.

Sequence Detection

Unusual Login
 + New Access Key
 + IAM Policy Change
 + Sensitive Resource Change
 = Investigation

Response

  1. Validate.
  2. Identify principal.
  3. Determine authorization.
  4. Review related events.
  5. Contain suspected compromise.
  6. Rotate/revoke credentials.
  7. Preserve evidence.
  8. Investigate lateral movement.

Final Takeaway

Detection improves when you model unexpected identity behavior and attack sequences instead of simply matching suspicious API names.

Dikshant Lather
Written by

Dikshant Lather

Cyber Security & AI Architect

Responses (0)

Join the technical conversation or share implementation thoughts.

What are your thoughts?

Sign in to join the technical discussion or share feedback.

There are currently no responses for this story. Be the first to respond.