ISIT Security LabsIncident response training

NexusCore Technologies · IAM / security-automation service account

AWS IAM Credential Compromise Investigation

Intermediate30 minCloud Security / Identity Security / Incident Response
Now: Case briefing. Read the ticket and environment first. Do not open logs until you know what you are looking for.

Ticket summary

On 14 August 2026 NexusCore Technologies received a GuardDuty HIGH severity alert indicating that IAM user 'security-automation' performed API calls from an external IP address inconsistent with any known AWS service. Sensitive finance S3 bucket activity was also detected. You are the investigating SOC analyst.

NexusCore Technologies runs a suite of compliance and security automation workflows using a dedicated IAM user 'security-automation'. This account holds the access key AKIAEXAMPLE7K3MNOP91 and operates from its normal CI/CD infrastructure based in ap-south-1 using IP 198.51.100.25.

At approximately 09:51 UTC, GuardDuty raised a HIGH-severity finding of type UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS. API calls were observed from 203.0.113.42 (eu-west-1), a source IP completely unrelated to NexusCore infrastructure.

The ticket includes CloudTrail logs for the full investigation window, the GuardDuty finding, IAM user metadata, and the access key record. Your job is to establish the attack timeline, determine what reconnaissance and privilege-escalation was attempted, assess what sensitive data was accessed, and recommend containment.