Platform Author Last Update aws Nick Jones 2024-12-02
An adversary may attempt to enumerate the configured IAM groups within an account, to identify entities that they might wish to gain access to or backdoor.
MITRE IDs
Required Permissions
Required Parameters
None
Attacker Action
Detection Case
ELK query
When logs are ingested into ELK, the following Lucene query can be used to identify relevant events.
eventName:ListGroups AND eventSource:*.iam.amazonaws.com
Sigma Definition
title : Enumerate IAM groups
id : 88d0e794-1e66-4d93-bf3b-4628bd09aaa3
description : An adversary may attempt to enumerate the configured IAM groups within an account, to identify entities that they might wish to gain access to or backdoor.
- eventSource : " *.iam.amazonaws.com "
- eventName : " ListGroups "
condition : selection_source and events
- Developers making legitimate changes to the environment. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.