AWS Threat Hunting Ideas: SQS
Overview:
1. Unauthorized Queue Creation (CreateQueue)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=CreateQueue
2. Queue Policy Modification (SetQueueAttributes)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=SetQueueAttributes
3. Suspicious Message Consumption (ReceiveMessage)
4. Deleting Messages from Queues (DeleteMessage/DeleteMessageBatch)
5. Deleting Queues (DeleteQueue)
6. Unauthorized Access (AddPermission/RemovePermission)
7. Message Injection or Spamming (SendMessage/SendMessageBatch)
8. Changes to Dead-Letter Queues (SetQueueAttributes)
9. Cross-Account Queue Access Abuse (AddPermission)
Last updated