Open cardosec

Case A10D2C · Cloud · L5 Expert

Attacker Persisting in AWS

Practise as: Incident drill · Deep dive

Live alertAn attacker held AdministratorAccess in a production AWS account for 9 days. Their original access key is deactivated, yet new API calls keep appearing.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Deactivating a key does not kill STS session tokens minted from it; revoke role sessions and deny the user explicitly
  2. Hunt IAM persistence: new users/keys, trust policies naming external accounts, new SAML/OIDC providers
  3. Hunt compute backdoors: Lambda and EventBridge triggers, EC2 user data, modified launch templates, AMIs or ECR images
  4. Scope first, then evict in one coordinated pass; partial cleanup tips off the actor to fall back to unseen persistence
  5. During recovery: SCP denying IAM changes except via a break-glass role, and CloudTrail kept in a separate log account

If the interviewer pushes back

  • How does the IAM revoke-sessions action work under the hood, and why does it not affect sessions issued afterwards?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.