elastic
high
kql
AWS Sensitive IAM Operations Performed via CloudShell
Identifies sensitive AWS IAM operations performed via AWS CloudShell based on the user agent string. CloudShell is a
browser-based shell that provides command-line access to AWS resources directly from the AWS Management Console. While
convenient for administrators, CloudShell access from compromised console sessions can enable attackers to perform
privileged operations without installing tools or using programmatic credentials. This rule detects high-risk actions
such as creating IAM users, acc