Case A10D2C · Cloud · L5 Expert
Attacker Persisting in AWS
Practise as: Incident drill · Deep dive
Live alertAn attacker held AdministratorAccess in a production AWS account for 9 days. Their original access key is deactivated, yet new API calls keep appearing.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Deactivating a key does not kill STS session tokens minted from it; revoke role sessions and deny the user explicitly
- Hunt IAM persistence: new users/keys, trust policies naming external accounts, new SAML/OIDC providers
- Hunt compute backdoors: Lambda and EventBridge triggers, EC2 user data, modified launch templates, AMIs or ECR images
- Scope first, then evict in one coordinated pass; partial cleanup tips off the actor to fall back to unseen persistence
- During recovery: SCP denying IAM changes except via a break-glass role, and CloudTrail kept in a separate log account
If the interviewer pushes back
- How does the IAM revoke-sessions action work under the hood, and why does it not affect sessions issued afterwards?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.