AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.
- Product
- aws
- Service
- cloudtrail
- Author
- daniel.bohannon@permiso.io (@danielhbohannon) (SigmaHQ), DRL 1.1
- Published
- 2023-05-17
- Updated
- 2026-07-31
ATT&CK techniques
Initial Access → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags AWS CloudTrail events where IAM users or access keys are created and the request user agent contains "S3 Browser". Creating IAM credentials is a common step for establishing persistence and enabling authenticated access to AWS resources. The detection relies on CloudTrail IAM CreateUser and CreateAccessKey events correlated with the client user agent string.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "AWS CloudTrail: S3 Browser Creates IAM User or Access Key"
id: 52c64136-c7c0-457a-8c3a-5aca798566d6
status: test
description: This rule flags AWS CloudTrail events where IAM users or access keys are created and the request user agent contains "S3 Browser". Creating IAM credentials is a common step for establishing persistence and enabling authenticated access to AWS resources. The detection relies on CloudTrail IAM CreateUser and CreateAccessKey events correlated with the client user agent string.
references:
- https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_iam_s3browser_user_or_accesskey_creation.yml
author: daniel.bohannon@permiso.io (@danielhbohannon), Huntrule Team
date: 2023-05-17
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.initial-access
- attack.stealth
- attack.t1059.009
- attack.t1078.004
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: iam.amazonaws.com
eventName:
- CreateUser
- CreateAccessKey
userAgent|contains: S3 Browser
condition: selection
falsepositives:
- Valid usage of S3 Browser for IAM User and/or AccessKey creation
level: high
license: DRL-1.1
related:
- id: db014773-d9d9-4792-91e5-133337c0ffee
type: derived