THREAT OPS › Threat News › Investigating Persistence Mechanisms in AWS
Investigating Persistence Mechanisms in AWS
<h2>Overview</h2><p>In the cloud, your infrastructure may be short-lived, but an attacker’s persistence doesn't have to be. While your environment scales and changes in seconds, adversaries are embedding themselves into your IAM policies, Lambda functions, and federated sessions, creating invisible footholds that survive long after you believe an incident is closed.</p><p>Persistence in AWS is not
MITRE ATT&CK techniques
- ServerlessT1583.007
- CredentialsT1589.001
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- https://uniqueaddress.lambda-url.us-east-1.on.aws/url