Detecting Automated AWS Privilege Escalation: CloudTrail, GuardDuty and Athena Queries
When attackers move at machine speed, detection must focus on early, high-signal events and trigger automatic containment. These detections target fast privilege escalation in AWS.
Signals worth watching
- First use of an access key from a new IP followed within minutes by IAM enumeration (
ListUsers,ListRoles,GetAccountAuthorizationDetails). UpdateFunctionCode,CreateFunctionorUpdateFunctionConfigurationfollowed by invocation of a function with a privileged role.iam:PassRolecombined with compute creation by unexpected identities.- New access keys or roles created by a principal that just appeared.
- Sudden Bedrock
InvokeModelvolume or GPU instance launches. - GuardDuty findings for anomalous behavior and privilege escalation.
Where the data lives
- CloudTrail (management events in all regions).
- GuardDuty (including Lambda Protection and runtime monitoring).
- Cost Anomaly Detection and Budgets.
A starting query
A principal performing enumeration and Lambda changes within 30 minutes:
AWSCloudTrail
| where TimeGenerated > ago(1d)
| summarize Enum = countif(EventName in ("ListUsers", "ListRoles", "GetAccountAuthorizationDetails", "ListAttachedRolePolicies")),
LambdaChanges = countif(EventName has_any ("CreateFunction", "UpdateFunctionCode", "UpdateFunctionConfiguration")),
Keys = countif(EventName == "CreateAccessKey")
by UserIdentityArn, SourceIpAddress, bin(TimeGenerated, 30m)
| where Enum > 3 and (LambdaChanges > 0 or Keys > 0)
Automated response
For matches with high confidence, trigger automation to:
- Attach an inline deny-all policy to the principal (or revoke sessions).
- Deactivate associated access keys.
- Notify the on-call responder.
Then investigate — with the attacker already contained.