Possible SES Sending Configuration Enumeration via CloudTrail

PremiumReviewedSigma · Low · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-09-14
Updated
2026-09-14

ATT&CK techniques

Initial Access → Discovery
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects reconnaissance enumeration of Amazon SES sending configuration through GetAccountSendingEnabled, GetSendQuota, ListIdentities, and GetIdentityVerificationAttributes calls. Adversaries with stolen credentials probe SES quotas and verified identities to determine whether the account can be abused to send spam or phishing. A burst of these read calls from an unexpected principal often precedes SES abuse.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Suspicious Boto3 Kali Linux User Agent in AWS CloudTrail Reconnaissance (via cloudtrail)
Suspicious AWS Role Assumption via Cognito Web Identity
Suspicious Google Cloud Function Create or Update Triggering Build
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Possible SES Sending Configuration Enumeration via CloudTrail
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.