Detecting Exposed Environment Variables: CloudTrail, GuardDuty and Athena Queries
Retrospective: this article looks back at events from August 2024, written in 2026 with the benefit of hindsight.
Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion campaigns.
Signals worth watching
GetCallerIdentityfrom an IP not associated with your workloads, followed byListUsers,ListBuckets,ListRoles.CreateRole,AttachRolePolicywithAdministratorAccess, orPutRolePolicyby application credentials.CreateFunction(Lambda) by unexpected identities.- Large S3
GetObjectvolumes followed byDeleteObjectorDeleteObjects. - New objects named like ransom notes.
- GuardDuty findings for anomalous behavior or exfiltration.
Where the data lives
- CloudTrail management events and S3 data events.
- GuardDuty (including S3 Protection).
- IAM Access Analyzer for new external access.
A starting query
Privilege escalation attempts by non-admin identities:
AWSCloudTrail
| where EventName in ("CreateRole", "AttachRolePolicy", "PutRolePolicy", "CreateUser",
"AttachUserPolicy", "CreateAccessKey", "CreateFunction20150331", "CreateFunction")
| where UserIdentityArn !has "AdminRole" and UserIdentityArn !has "Terraform"
| project TimeGenerated, EventName, UserIdentityArn, SourceIpAddress, RequestParameters
Replace the exclusions with your known admin and automation roles.
Response
- Deactivate compromised keys.
- Delete attacker-created roles, users and Lambda functions.
- Restore deleted data from versions or backups.
- Find and remove the exposed configuration file.
- Exposed .env Files Fuel an AWS Extortion Campaign (Aug 2024) Incident Teardowns
- How to Keep Secrets Out of Web Roots and Into AWS Secrets Manager How-To & Hardening
- CIO Brief: Leaked Configuration Files Are Leaked Keys CIO Briefings