AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile
Flags CloudTrail IAM GetLoginProfile and CreateLoginProfile activity initiated by an S3 Browser user agent.
- Product
- aws
- Service
- cloudtrail
- Author
- daniel.bohannon@permiso.io (@danielhbohannon) (SigmaHQ), DRL 1.1
- Published
- 2023-05-17
- Updated
- 2026-07-31
ATT&CK techniques
Initial Access → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies AWS CloudTrail activity where the S3 Browser user agent issues IAM GetLoginProfile and CreateLoginProfile requests. Attackers can use these actions to enumerate login-related configuration and establish persistence by creating new IAM LoginProfiles. Detection relies on CloudTrail records for iam.amazonaws.com events and matching the S3 Browser string in the user agent.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile"
id: 3baa69a2-0ec3-446f-9038-367a718355cb
status: test
description: This rule identifies AWS CloudTrail activity where the S3 Browser user agent issues IAM GetLoginProfile and CreateLoginProfile requests. Attackers can use these actions to enumerate login-related configuration and establish persistence by creating new IAM LoginProfiles. Detection relies on CloudTrail records for iam.amazonaws.com events and matching the S3 Browser string in the user agent.
references:
- https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_iam_s3browser_loginprofile_creation.yml
author: daniel.bohannon@permiso.io (@danielhbohannon), Huntrule Team
date: 2023-05-17
tags:
- attack.execution
- attack.persistence
- attack.initial-access
- attack.privilege-escalation
- attack.stealth
- attack.t1059.009
- attack.t1078.004
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: iam.amazonaws.com
eventName:
- GetLoginProfile
- CreateLoginProfile
userAgent|contains: S3 Browser
condition: selection
falsepositives:
- Valid usage of S3 Browser for IAM LoginProfile listing and/or creation
level: high
license: DRL-1.1
related:
- id: db014773-b1d3-46bd-ba26-133337c0ffee
type: derived