Elastic medium stable kql

AWS Secrets Manager Rapid Secrets Retrieval

Identifies rapid secret retrieval activity from AWS Secrets Manager using the GetSecretValue or BatchGetSecretValue API actions. Adversaries who compromise an IAM user, instance role, or temporary credentials may attempt to enumerate or exfiltrate secrets in bulk to escalate privileges, move laterally, or gain persistence. This rule detects 20 or more unique secret retrievals by the same user identity within a short time window, which may indicate credential compromise or automated secret harvesting.

View Source

Detection Logic

data_stream.dataset: "aws.cloudtrail" 
    and event.provider: "secretsmanager.amazonaws.com" 
    and event.action: "GetSecretValue" 
    and event.outcome: "success" 
    and not (
        user_agent.name: ("Chrome" or "Firefox" or "Safari" or "Edge" or "Brave" or "Opera") 
        or source.address: ("kafka.amazonaws.com" or "apidestinations.events.amazonaws.com")
    )

False Positives

  • Verify whether the user identity, user agent, and/or hostname should be using GetSecretValue or BatchGetSecretValue APIs for the specified SecretId. If known behavior is causing false positives, it can be exempted from the rule.

Field Validations

Loading…

Comments (0)

Loading comments...