- 필수 기능
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- 디지털 경험
- 소프트웨어 제공
- 보안
- 로그 관리
- 관리
- 인프라스트럭처
- ci
- containers
- csm
- ndm
- otel_guides
- overview
- slos
- synthetics
- tests
- 워크플로
Classification:
attack
Tactic:
Technique:
Detect when an AWS secret is retrieved from an AWS CloudShell environment.
Monitor CloudTrail and detect when an AWS secret is retrieved from an AWS CloudShell environment. The threat group LUCR-3 uses AWS CloudShell in the AWS management console to carry out activities that require direct interaction with the AWS API, such as the retrieval of secrets.
{{@userIdentity.arn}}
should have carried out this operation.