AWSDetection & ResponseRetrospectives

Detecting Exposed Environment Variables: CloudTrail, GuardDuty and Athena Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2024, written in 2026 with the benefit of hindsight.

Credential theft from exposed configuration files leads to predictable AWS activity. These detections target the patterns seen in .env-based extortion campaigns.

Signals worth watching

  • GetCallerIdentity from an IP not associated with your workloads, followed by ListUsers, ListBuckets, ListRoles.
  • CreateRole, AttachRolePolicy with AdministratorAccess, or PutRolePolicy by application credentials.
  • CreateFunction (Lambda) by unexpected identities.
  • Large S3 GetObject volumes followed by DeleteObject or DeleteObjects.
  • New objects named like ransom notes.
  • GuardDuty findings for anomalous behavior or exfiltration.

Where the data lives

  • CloudTrail management events and S3 data events.
  • GuardDuty (including S3 Protection).
  • IAM Access Analyzer for new external access.

A starting query

Privilege escalation attempts by non-admin identities:

AWSCloudTrail
| where EventName in ("CreateRole", "AttachRolePolicy", "PutRolePolicy", "CreateUser",
    "AttachUserPolicy", "CreateAccessKey", "CreateFunction20150331", "CreateFunction")
| where UserIdentityArn !has "AdminRole" and UserIdentityArn !has "Terraform"
| project TimeGenerated, EventName, UserIdentityArn, SourceIpAddress, RequestParameters

Replace the exclusions with your known admin and automation roles.

Response

  1. Deactivate compromised keys.
  2. Delete attacker-created roles, users and Lambda functions.
  3. Restore deleted data from versions or backups.
  4. Find and remove the exposed configuration file.
detect exposed environment variablesExposed .env files extortion2024

More on this story