Skip to content

new: AWS SES Account Availability Discovery Via Long-Lived Access Key#6043

Open
marcopedrinazzi wants to merge 2 commits into
SigmaHQ:masterfrom
marcopedrinazzi:ses-discovery
Open

new: AWS SES Account Availability Discovery Via Long-Lived Access Key#6043
marcopedrinazzi wants to merge 2 commits into
SigmaHQ:masterfrom
marcopedrinazzi:ses-discovery

Conversation

@marcopedrinazzi

Copy link
Copy Markdown
Contributor

Summary of the Pull Request

New rule to detect AWS SES Account Availability Discovery Via Long-Lived Access Key. Refs: https://www.datadoghq.com/blog/detect-phishing-activity-amazon-ses/ and https://www.wiz.io/blog/wiz-discovers-cloud-email-abuse-campaign.
GetSendQuota was triggered via an AWS keys canary that i placed in a honeypot too.

Changelog

new: AWS SES Account Availability Discovery Via Long-Lived Access Key

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions Bot added Rules Review Needed The PR requires review labels Jun 2, 2026
@SigmaHQ SigmaHQ deleted a comment from github-actions Bot Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant