Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0130 — Detect Unauthorized Access to Cloud Secrets Management Stores
DET0130

Detect Unauthorized Access to Cloud Secrets Management Stores

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0366 Analytic 0366
IaaS

Detection of suspicious access to cloud-native secret management systems (AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, HashiCorp Vault). Focuses on abnormal secret retrieval activity, such as secrets being accessed by unusual identities, from unexpected regions, outside business hours, or at high volume. Correlates API calls to secret retrieval with surrounding authentication events, role assumptions, and anomalous execution patterns.

AWS:CloudTrail GetSecretValue
[PrivilegedRoles] Set of accounts or roles allowed to retrieve secrets; deviations may indicate misuse.
[TimeWindow] Temporal window to correlate secret access with authentication and anomalous context.
[AccessPatterns] Expected frequency and volume of secret retrievals per user/service; anomalies may indicate exfiltration.
[RegionConstraints] Regions in which secret access is expected; access from unusual geographies may indicate compromise.

Detected Techniques

1

Details

MITRE ID
DET0130
STIX ID
x-mitre-detection-strategy--f69d3378-a034-4709-9778-6efd2269e097
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.