AWS CloudTrail: S3 Browser Creates IAM User or Access Key

Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.

FreeReviewedSigma · High · v5
Product
aws
Service
cloudtrail
Author
daniel.bohannon@permiso.io (@danielhbohannon) (SigmaHQ), DRL 1.1
Published
2023-05-17
Updated
2026-07-31
title: "AWS CloudTrail: S3 Browser Creates IAM User or Access Key"
id: 52c64136-c7c0-457a-8c3a-5aca798566d6
status: test
description: This rule flags AWS CloudTrail events where IAM users or access keys are created and the request user agent contains "S3 Browser". Creating IAM credentials is a common step for establishing persistence and enabling authenticated access to AWS resources. The detection relies on CloudTrail IAM CreateUser and CreateAccessKey events correlated with the client user agent string.
references:
  - https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_iam_s3browser_user_or_accesskey_creation.yml
author: daniel.bohannon@permiso.io (@danielhbohannon), Huntrule Team
date: 2023-05-17
tags:
  - attack.privilege-escalation
  - attack.execution
  - attack.persistence
  - attack.initial-access
  - attack.stealth
  - attack.t1059.009
  - attack.t1078.004
logsource:
  product: aws
  service: cloudtrail
detection:
  selection:
    eventSource: iam.amazonaws.com
    eventName:
      - CreateUser
      - CreateAccessKey
    userAgent|contains: S3 Browser
  condition: selection
falsepositives:
  - Valid usage of S3 Browser for IAM User and/or AccessKey creation
level: high
license: DRL-1.1
related:
  - id: db014773-d9d9-4792-91e5-133337c0ffee
    type: derived