Redundant Access T1108

Tactics: Stealth, Persistence

**This technique has been deprecated. Please use Create Account, Web Shell, and External Remote Services where appropriate.**

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
aws::eventName3eq 2, in 1UpdateLoginProfile, CreateAccessKey, CreateLoginProfile, DeleteLoginProfile
aws::eventSource3eq 3iam.amazonaws.com
requestParameters.passwordResetRequired2is_null 2

Top indicator values (6 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
aws::eventSourceeq
iam.amazonaws.com
328
aws::eventNameeq
CreateAccessKey
13
aws::eventNameeq
UpdateLoginProfile
1
aws::eventNamein
CreateLoginProfile
12
aws::eventNamein
DeleteLoginProfile
1
aws::eventNamein
UpdateLoginProfile
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: AWS

Domain: Cloud

Panther 3 rules