Detection rules › Sigma

IAM Access Key Creation Attempt

Status
test
Severity
medium
Log source
product aws, service cloudtrail
Author
nishikawaakira (@nishikawaakira)
Source
github.com/Yamato-Security/suzaku-rules

Detects a failed attempt to create an IAM access key (AccessDenied). Even though the attempt failed, it indicates the attacker has valid credentials and is attempting persistence via access key creation.

MITRE ATT&CK coverage

Telemetry coverage

Rules detecting the same action

These rules filter on the same operation.

Rule body

title: IAM Access Key Creation Attempt
id: 2c4d6e8f-0a1b-3c5d-7e9f-1a2b3c4d5e70
status: test
description: |
    Detects a failed attempt to create an IAM access key (AccessDenied).
    Even though the attempt failed, it indicates the attacker has valid
    credentials and is attempting persistence via access key creation.
references:
    - https://attack.mitre.org/techniques/T1098/001/
    - https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccessKey.html
author: nishikawaakira (@nishikawaakira)
date: 2026-05-03
modified: 2026-05-29
tags:
    - attack.persistence
    - attack.t1098.001
logsource:
    product: aws
    service: cloudtrail
detection:
    selection:
        eventSource: iam.amazonaws.com
        eventName: CreateAccessKey
        errorCode: AccessDenied
    condition: selection
falsepositives:
level: medium

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    eventSource: iam.amazonaws.com
    eventName: CreateAccessKey
    errorCode: AccessDenied

Indicators

These rows show field, operator, and value matches.