Primary email update request

이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우 언제든지 연락주시기 바랍니다.

Goal

Detect when an API call is made to update the primary email address for an account.

Strategy

Monitor CloudTrail and detect when the API call StartPrimaryEmailUpdate is called in an attempt to change the primary email of an AWS account.

Triage and response

  1. Determine if the API call {{@evt.name}} should have been made by the user {{@userIdentity.arn}} from the IP address {{@network.client.ip}} .
  2. If the action is legitimate, consider including the user in a suppression list. See Best practices for creating detection rules with Datadog Cloud SIEM for more information.
  3. If the action shouldn’t have happened:
    • Contact the user ({{@userIdentity.arn}}) and see if they made the API call.
    • Use the Cloud SIEM - User Investigation dashboard to see if the user ({{@userIdentity.arn}}) has taken other actions.
    • Use the Cloud SIEM - IP Investigation dashboard to see if there’s more traffic from the IP {{@network.client.ip}}.
  4. If the results of the triage indicate that an attacker has taken the action, initiate your company’s incident response process, as well as an investigation.
PREVIEWING: brett.blue/embedded-collector-nav