IAM Enumeration sequence

Cortex XSIAM Analytics Alert Reference by Alert name

Product
Cortex XSIAM
Last date published
2026-05-10
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

7 Days

Required Data

  • Requires one of the following data sources:
    • AWS Audit Log
      OR
    • Gcp Audit Log

Detection Modules

Cloud

Detector Tags

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Severity

Informational

Description

An identity has executed a sequence of events which may be related to an IAM recon enumeration.

Attacker's Goals

Gather information about the cloud environment, including IAM users, groups, roles, and policies.

Investigative actions

Verify whether the API calls were made by the identity and check for any additional related calls.

Variations

IAM Enumeration sequence executed from a cloud Internet facing instance

Synopsis

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Severity

Low

Description

A cloud Internet facing instance performed an unusual IAM enumeration.

Attacker's Goals

Gather information about the cloud environment, including IAM users, groups, roles, and policies.

Investigative actions

Verify whether the API calls were made by the identity and check for any additional related calls.