Detection rules › Sigma
IAM Access Key Creation Attempt
Detects a failed attempt to create an IAM access key (AccessDenied). Even though the attempt failed, it indicates the attacker has valid credentials and is attempting persistence via access key creation.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Persistence |
Telemetry coverage
Rules detecting the same action
These rules filter on the same operation.
- AWS IAM Backdoor Users Keys (Sigma)
- AWS IAM Credentials Added to a Bedrock API Key Phantom User (Elastic)
- AWS IAM S3Browser User or AccessKey Creation (Sigma)
- AWS IAM Sensitive Operations via Lambda Execution Role (Elastic)
- AWS IAM User Created Access Keys For Another User (Elastic)
- AWS IAM User Self-Created Access Key Subsequently Used (Elastic)
- AWS Sensitive IAM Operations Performed via CloudShell (Elastic)
- AWS User API Key Created (Panther)
Rule body
title: IAM Access Key Creation Attempt
id: 2c4d6e8f-0a1b-3c5d-7e9f-1a2b3c4d5e70
status: test
description: |
Detects a failed attempt to create an IAM access key (AccessDenied).
Even though the attempt failed, it indicates the attacker has valid
credentials and is attempting persistence via access key creation.
references:
- https://attack.mitre.org/techniques/T1098/001/
- https://docs.aws.amazon.com/IAM/latest/APIReference/API_CreateAccessKey.html
author: nishikawaakira (@nishikawaakira)
date: 2026-05-03
modified: 2026-05-29
tags:
- attack.persistence
- attack.t1098.001
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: iam.amazonaws.com
eventName: CreateAccessKey
errorCode: AccessDenied
condition: selection
falsepositives:
level: medium
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
eventSource: iam.amazonaws.com
eventName: CreateAccessKey
errorCode: AccessDenied
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
errorCode | eq |
| field:"aws::errorCode" kind:eq value:"AccessDenied" |
eventName | eq |
| field:"aws::eventName" kind:eq value:"CreateAccessKey" |
eventSource | eq |
| field:"aws::eventSource" kind:eq value:"iam.amazonaws.com" |