elastic
medium
kql
AWS SES Full Access Policy Attached to IAM Entity by Unusual User
Detects the first occurrence in 7 days of an AWS identity attaching the managed policy
AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted
permission to send email, manage identities and templates, manage suppression lists, and access
SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly
created user or a role not previously associated with email operations, is a documented technique
used by threat actors to est