diff --git a/rules/cloud/aws_update_login_profile.yml b/rules/cloud/aws_update_login_profile.yml index 70bdbf8f7..b4f1b549e 100644 --- a/rules/cloud/aws_update_login_profile.yml +++ b/rules/cloud/aws_update_login_profile.yml @@ -1,4 +1,4 @@ -title: AWS updating an existing login profile +title: Updating the Login Profile of other users on AWS id: 0a5177f4-6ca9-44c2-aacf-d3f3d8b6e4d2 status: experimental description: An attacker with the iam:UpdateLoginProfile permission on other users can change the password used to login to the AWS console on any user that already has a login profile setup. With this alert, it is used to detect anyone is changing password on behalf of other users.