AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile

Flags CloudTrail IAM GetLoginProfile and CreateLoginProfile activity initiated by an S3 Browser user agent.

FreeReviewedSigma · High · v5
Product
aws
Service
cloudtrail
Author
daniel.bohannon@permiso.io (@danielhbohannon) (SigmaHQ), DRL 1.1
Published
2023-05-17
Updated
2026-07-31
title: "AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile"
id: 3baa69a2-0ec3-446f-9038-367a718355cb
status: test
description: This rule identifies AWS CloudTrail activity where the S3 Browser user agent issues IAM GetLoginProfile and CreateLoginProfile requests. Attackers can use these actions to enumerate login-related configuration and establish persistence by creating new IAM LoginProfiles. Detection relies on CloudTrail records for iam.amazonaws.com events and matching the S3 Browser string in the user agent.
references:
  - https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_iam_s3browser_loginprofile_creation.yml
author: daniel.bohannon@permiso.io (@danielhbohannon), Huntrule Team
date: 2023-05-17
tags:
  - attack.execution
  - attack.persistence
  - attack.initial-access
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1059.009
  - attack.t1078.004
logsource:
  product: aws
  service: cloudtrail
detection:
  selection:
    eventSource: iam.amazonaws.com
    eventName:
      - GetLoginProfile
      - CreateLoginProfile
    userAgent|contains: S3 Browser
  condition: selection
falsepositives:
  - Valid usage of S3 Browser for IAM LoginProfile listing and/or creation
level: high
license: DRL-1.1
related:
  - id: db014773-b1d3-46bd-ba26-133337c0ffee
    type: derived