Idea for a correlation rule in SIEM
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Idea for a SIEM correlation rule 💡
Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simplest signal to implement is the user creation event itself.
IF eventName = CreateUser AND userIdentity points to a Lambda function role (userIdentity.inScopeOf.issuerType = AWS::Lambda::Function),
THEN generate a high-priority alert.
Given that creating users via Lambda functions is extremely rare and anomalous behavior, such a rule will have a very low false positive rate.
Sigma rule:
title: Suspicious IAM User Creation by AWS Lambda Function
id: 700feb27-05a5-4ba1-ae80-2c8d0d3591eb
status: test
description: >-
Detects the creation or modification of an IAM user/credentials where the action is initiated by an AWS Lambda function's execution role.
This is a highly anomalous behavior and a key indicator of the "Persistence-as-a-Service" technique,
where an attacker uses a Lambda function (often exposed via an open API Gateway) to create backdoor users.
references:
- https://securitylabs.datadoghq.com/articles/tales-from-the-cloud-trenches-the-attacker-doth-persist-too-much/
author: 'PT ESC'
date: '2025/09/20'
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventName:
- CreateUser
- CreateAccessKey
- AttachUserPolicy
- UpdateLoginProfile
userIdentity.inScopeOf.issuerType: 'AWS::Lambda::Function'
condition: selection
falsepositives:
- Legitimate workflows that use Lambda to automatically create users (e.g., a custom registration portal). These functions should be added to the exceptions.
level: high
This experiment once again proved that monitoring the actions of the services themselves (not just users) is the key to cloud security. What other cloud persistence techniques have you encountered?
#detect #tip #sigma #reverse
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…







