Terminology Index

Glossary

1801 terms

Open concept maps

Showing 385-416 of 1801 terms

C
32

Compromised IAM Credentials Playbook

A cloud incident-response playbook for when cloud access keys or identity credentials are stolen, covering how to confirm the compromise, scope what the attacker did, revoke and rotate credentials, and recover, using cloud-native tools.

Stolen cloud credentials are one of the most common and dangerous cloud incidents, since identity is effectively the perimeter. The playbook sequences the response: confirm via detection signals, scope the attacker's actions through audit logs like CloudTrail, contain by disabling keys and revoking sessions, eradicate persistence the attacker created, and recover by rotating credentials and tightening access. Having it predefined lets responders act fast under pressure.

Introduced in: Cloud Incident Response

Examples

  • Disabling a leaked access key and revoking its active sessions immediately.
  • Scoping the attacker's API actions through CloudTrail before recovery.
  • Rotating affected credentials and removing any roles the attacker added.

No related terms linked yet.