AWS Access Key
UnlockedIAM access key that alerts on API usage
Type
PersistentDetection
InstantMITRE ATT&CK
max 10 tokens
AWS Bedrock Key
UnlockedBedrock service-specific credentials that alert on AI/ML API usage
Type
PersistentDetection
InstantMITRE ATT&CK
max 2 tokens
AWS Bedrock Bearer Token
LockedAWS Bedrock bearer token
Type
EphemeralDetection
InstantMITRE ATT&CK
AWS DSQL Token
LockedEphemeral Aurora DSQL connection token (36 hours)
Type
EphemeralDetection
<1minMITRE ATT&CK
AWS ECR Token
LockedEphemeral container registry token (12 hours)
Type
EphemeralDetection
InstantMITRE ATT&CK
AWS Federation Token
LockedEphemeral federated session credentials (15min - 36hr)
Type
EphemeralDetection
InstantMITRE ATT&CK
AWS Presigned URL
LockedEphemeral S3 object access URL (up to 7 days)
Type
EphemeralDetection
InstantMITRE ATT&CK
AWS RDS MySQL User
LockedMySQL user that alerts on connection attempts
Type
PersistentDetection
<1minMITRE ATT&CK
AWS RDS Postgres User
LockedPostgreSQL user that alerts on connection attempts
Type
PersistentDetection
<1minMITRE ATT&CK
AWS S3 Bucket
UnlockedS3 bucket that alerts on access
Type
PersistentDetection
InstantMITRE ATT&CK
max 2 tokens
AWS Session Token
LockedEphemeral session credentials (15min - 36hr)
Type
EphemeralDetection
InstantMITRE ATT&CK
AWS User Credential
LockedIAM console login credentials that alert on sign-in
Type
PersistentDetection
InstantMITRE ATT&CK
Azure Service Principal
LockedService principal that alerts on authentication
Type
PersistentDetection
<1minMITRE ATT&CK
CrowdStrike API Key
LockedCrowdStrike API credentials that alert on usage
Type
PersistentDetection
<5minMITRE ATT&CK
SSH Private Key
UnlockedSSH key that alerts on authentication attempts
Type
PersistentDetection
InstantMITRE ATT&CK
max 20 tokens
Web Clone Token
LockedWeb resource that alerts on access from unexpected domains
Type
PersistentDetection
InstantMITRE ATT&CK