AWS SES Enumeration via Long-Term Access Key
Detects enumeration of Amazon Simple Email Service (SES) resources using long-term IAM access keys (AKIA* prefix). Long-term access keys are associated with IAM users and are the credential type most commonly exfiltrated from repositories, configuration files, and environment variables. An adversary who obtains a long-term key may enumerate SES to discover verified email identities, sending quotas, and DKIM/MAIL FROM domain configurations as a precursor to phishing or spam campaigns launched from the compromised account's verified domains.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/08/24"
3integration = ["aws"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Detects enumeration of Amazon Simple Email Service (SES) resources using long-term IAM access
11keys (AKIA* prefix). Long-term access keys are associated with IAM users and are the credential
12type most commonly exfiltrated from repositories, configuration files, and environment variables.
13An adversary who obtains a long-term key may enumerate SES to discover verified email identities,
14sending quotas, and DKIM/MAIL FROM domain configurations as a precursor to phishing or spam
15campaigns launched from the compromised account's verified domains.
16"""
17false_positives = [
18 """
19 Automated monitoring scripts, infrastructure inventory tools, or CI/CD pipelines that use
20 long-term IAM keys to audit SES configuration will trigger this rule. Migrate automation
21 to IAM roles with short-lived credentials; long-term keys used for SES management are a
22 security anti-pattern regardless of this alert.
23 """,
24]
25from = "now-6m"
26index = ["logs-aws.cloudtrail-*"]
27language = "kuery"
28license = "Elastic License v2"
29name = "AWS SES Enumeration via Long-Term Access Key"
30note = """## Triage and analysis
31
32### Investigating AWS SES Enumeration via Long-Term Access Key
33
34Amazon SES verified identities (email addresses and domains) are the sending credentials that allow SES to send email on behalf of a domain. Adversaries who exfiltrate long-term IAM keys may enumerate SES to identify available verified domains for phishing, discover DKIM configurations, or check sending limits before launching a bulk email campaign.
35
36Long-term keys (AKIA* prefix) are lower-security than assumed-role credentials: they do not expire and are frequently exposed in source code, .env files, CI/CD configuration, and developer workstations. This makes them the most common compromised credential type in cloud environments.
37
38### Possible investigation steps
39
40- Identify the IAM user behind the long-term key from aws.cloudtrail.user_identity.arn.
41- Check whether this access key has been rotated recently (GetAccessKeyLastUsed, ListAccessKeys). Confirm the user who owns the key initiated this activity.
42- Review source.ip and source.as.organization.name against known developer or automation infrastructure. API calls from unexpected geographies using a long-term key are high-risk.
43- Query CloudTrail for subsequent SES write operations (SendEmail, SendRawEmail, VerifyEmailIdentity, UpdateAccountSendingEnabled) using the same access key.
44- Check GitHub, GitLab, and CI/CD logs for any public exposure of this key.
45
46### Response and remediation
47
48- Immediately deactivate the long-term access key (UpdateAccessKey --status Inactive).
49- Rotate all credentials associated with the IAM user.
50- Review all SES quotas and sending history to determine whether unauthorized email was sent.
51- Migrate automation that used this key to IAM roles with short-lived assumed-role credentials.
52"""
53references = [
54 "https://docs.aws.amazon.com/ses/latest/APIReference/API_ListIdentities.html",
55 "https://permiso.io/blog/s/aws-ses-pionage-detecting-ses-abuse/",
56 "https://stratus-red-team.cloud/attack-techniques/AWS/aws.discovery.ses-enumerate/",
57]
58risk_score = 21
59rule_id = "8d05971b-5858-4b72-b09a-17e3cee0af54"
60setup = "The AWS integration must be ingesting management events into `logs-aws.cloudtrail-*`. SES management APIs are logged by default."
61severity = "low"
62tags = [
63 "Domain: Cloud",
64 "Data Source: AWS",
65 "Data Source: Amazon Web Services",
66 "Platform: AWS",
67 "Data Source: AWS CloudTrail",
68 "Service: AWS SES",
69 "Rule Type: Custom Query (KQL)",
70 "Tactic: Discovery",
71 "Resources: Investigation Guide",
72]
73timestamp_override = "event.ingested"
74type = "query"
75
76query = '''
77data_stream.dataset: "aws.cloudtrail"
78 and event.provider: "ses.amazonaws.com"
79 and event.action: (
80 "ListIdentities" or
81 "GetAccountSendingEnabled" or
82 "GetSendQuota" or
83 "ListEmailIdentities" or
84 "GetEmailIdentity" or
85 "DescribeActiveReceiptRuleSet" or
86 "ListReceiptRuleSets"
87 )
88 and event.outcome: "success"
89 and aws.cloudtrail.user_identity.access_key_id: AKIA*
90'''
91
92
93[[rule.threat]]
94framework = "MITRE ATT&CK"
95[[rule.threat.technique]]
96id = "T1526"
97name = "Cloud Service Discovery"
98reference = "https://attack.mitre.org/techniques/T1526/"
99
100
101[rule.threat.tactic]
102id = "TA0007"
103name = "Discovery"
104reference = "https://attack.mitre.org/tactics/TA0007/"
105
106[rule.investigation_fields]
107field_names = [
108 "@timestamp",
109 "aws.cloudtrail.user_identity.arn",
110 "aws.cloudtrail.user_identity.type",
111 "aws.cloudtrail.user_identity.access_key_id",
112 "user.name",
113 "event.action",
114 "event.outcome",
115 "source.ip",
116 "source.as.organization.name",
117 "cloud.region",
118 "cloud.account.id",
119]
Triage and analysis
Investigating AWS SES Enumeration via Long-Term Access Key
Amazon SES verified identities (email addresses and domains) are the sending credentials that allow SES to send email on behalf of a domain. Adversaries who exfiltrate long-term IAM keys may enumerate SES to identify available verified domains for phishing, discover DKIM configurations, or check sending limits before launching a bulk email campaign.
Long-term keys (AKIA* prefix) are lower-security than assumed-role credentials: they do not expire and are frequently exposed in source code, .env files, CI/CD configuration, and developer workstations. This makes them the most common compromised credential type in cloud environments.
Possible investigation steps
- Identify the IAM user behind the long-term key from aws.cloudtrail.user_identity.arn.
- Check whether this access key has been rotated recently (GetAccessKeyLastUsed, ListAccessKeys). Confirm the user who owns the key initiated this activity.
- Review source.ip and source.as.organization.name against known developer or automation infrastructure. API calls from unexpected geographies using a long-term key are high-risk.
- Query CloudTrail for subsequent SES write operations (SendEmail, SendRawEmail, VerifyEmailIdentity, UpdateAccountSendingEnabled) using the same access key.
- Check GitHub, GitLab, and CI/CD logs for any public exposure of this key.
Response and remediation
- Immediately deactivate the long-term access key (UpdateAccessKey --status Inactive).
- Rotate all credentials associated with the IAM user.
- Review all SES quotas and sending history to determine whether unauthorized email was sent.
- Migrate automation that used this key to IAM roles with short-lived assumed-role credentials.
References
Related rules
- AWS Backup Resource Enumeration via Long-Term Access Key
- AWS SES Account Email Sending Enabled
- AWS Account Closed
- AWS Account Discovery By Rare User
- AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN