Elastic medium stable kql
AWS Secrets Manager Rapid Secrets Retrieval
Identifies rapid secret retrieval activity from AWS Secrets Manager using the GetSecretValue or BatchGetSecretValue API actions. Adversaries who compromise an IAM user, instance role, or temporary credentials may attempt to enumerate or exfiltrate secrets in bulk to escalate privileges, move laterally, or gain persistence. This rule detects 20 or more unique secret retrievals by the same user identity within a short time window, which may indicate credential compromise or automated secret harvesting.
Detection Logic
data_stream.dataset: "aws.cloudtrail"
and event.provider: "secretsmanager.amazonaws.com"
and event.action: "GetSecretValue"
and event.outcome: "success"
and not (
user_agent.name: ("Chrome" or "Firefox" or "Safari" or "Edge" or "Brave" or "Opera")
or source.address: ("kafka.amazonaws.com" or "apidestinations.events.amazonaws.com")
) False Positives
- ⚠ Verify whether the user identity, user agent, and/or hostname should be using GetSecretValue or BatchGetSecretValue APIs for the specified SecretId. If known behavior is causing false positives, it can be exempted from the rule.
Field Validations
Loading…
Comments (0)
Loading comments...