Detecting Compromised Cloud Credentials
Overview
Cybersecurity skill for detecting compromised cloud credentials. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"detecting compromised cloud credentials"
"Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing "
When investigating alerts about unusual cloud API activity from unfamiliar locations
When building detection rules for credential theft and abuse across cloud environments
When responding to notifications from cloud providers about exposed credentials
When monitoring for credential stuffing or brute force attacks against cloud identities
When assessing the scope of a credential compromise after initial detection
Do not use for preventing credential compromise (use MFA, credential rotation, and secrets management), for detecting application-level credential theft (use application security monitoring), or for endpoint credential harvesting detection (use EDR tools).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS GuardDuty enabled across all accounts and regions
- Azure Defender for Identity and Entra ID Protection configured
- GCP Security Command Center with Event Threat Detection enabled
- CloudTrail, Azure Activity Log, and GCP Audit Log centralized for analysis
- SIEM integration for cross-cloud correlation of credential abuse indicators
- Threat intelligence feeds for known malicious IP ranges
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Detection Scope — Identify the specific compromised cloud credentials techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.
- Collect Baseline Data — Gather historical logs and establish normal behavior patterns for compromised cloud credentials.
- Build Detection Queries — Write detection rules, Sigma rules, or SIEM queries targeting compromised cloud credentials indicators.
- Execute Hunts — Run queries against the collected data, starting with broad filters and narrowing down.
- Triage Results — Investigate alerts, filter false positives, and validate findings against known-good behavior.
- Document Findings — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.
Tools
- SIEM Platform — Central log aggregation and query execution
- Sigma Rules — Vendor-agnostic detection rule format
- MITRE ATT&CK Navigator — Technique mapping and coverage analysis
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: detecting-compromised-cloud-credentials3description: Use when detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection. . Use when working with detecting compromised cloud credentials.4license: Apache-2.05---67# Detecting Compromised Cloud Credentials89## Overview1011Cybersecurity skill for detecting compromised cloud credentials. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "detecting compromised cloud credentials"16- "Detecting compromised cloud credentials across AWS, Azure, and GCP by analyzing "171819- When investigating alerts about unusual cloud API activity from unfamiliar locations20- When building detection rules for credential theft and abuse across cloud environments21- When responding to notifications from cloud providers about exposed credentials22- When monitoring for credential stuffing or brute force attacks against cloud identities23- When assessing the scope of a credential compromise after initial detection2425**Do not use** for preventing credential compromise (use MFA, credential rotation, and secrets management), for detecting application-level credential theft (use application security monitoring), or for endpoint credential harvesting detection (use EDR tools).262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- AWS GuardDuty enabled across all accounts and regions38- Azure Defender for Identity and Entra ID Protection configured39- GCP Security Command Center with Event Threat Detection enabled40- CloudTrail, Azure Activity Log, and GCP Audit Log centralized for analysis41- SIEM integration for cross-cloud correlation of credential abuse indicators42- Threat intelligence feeds for known malicious IP ranges4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Define Detection Scope** — Identify the specific compromised cloud credentials techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.622. **Collect Baseline Data** — Gather historical logs and establish normal behavior patterns for compromised cloud credentials.633. **Build Detection Queries** — Write detection rules, Sigma rules, or SIEM queries targeting compromised cloud credentials indicators.644. **Execute Hunts** — Run queries against the collected data, starting with broad filters and narrowing down.655. **Triage Results** — Investigate alerts, filter false positives, and validate findings against known-good behavior.666. **Document Findings** — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.6768## Tools6970- **SIEM Platform** — Central log aggregation and query execution71- **Sigma Rules** — Vendor-agnostic detection rule format72- **MITRE ATT&CK Navigator** — Technique mapping and coverage analysis737475## Process76771. **Reconnaissance** — Gather target information, identify attack surface, enumerate services781. **Analysis/Exploitation** — Execute the technique, analyze results, document findings791. **Reporting** — Document IOCs, write findings, provide remediation recommendations8081## Verification8283- [ ] All compromised cloud credentials procedures executed completely and documented84- [ ] Findings validated against multiple data sources85- [ ] False positives identified and filtered86- [ ] Results documented with evidence and timestamps87- [ ] Recommendations provided with risk-based prioritization8889## Anti-Rationalization Table9091| Rationalization | Reality |92|---|---|93| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |94| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |95| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |