Ticket summary
On 19 August 2026 MeridianOps Cloud security monitoring detected unusual IAM configuration activity in the production AWS account. A normally low-privileged IAM identity began performing IAM changes inconsistent with its baseline, and shortly afterward elevated-privilege API activity was observed. You are the investigating SOC analyst.
MeridianOps Cloud operates a multi-team AWS account (851725491209) in ap-south-1. Engineering staff use named IAM users with customer-managed policies for day-to-day work. Privileged operations are intended to go through dedicated roles such as DeploymentRole and AdminRole.
At approximately 08:50 UTC, GuardDuty raised a HIGH-severity finding indicating that an IAM principal obtained administrative permissions and assumed a privileged role from an unusual source IP. The ticket includes CloudTrail management events for the investigation window, the GuardDuty finding, and IAM metadata for the implicated user.
Your job is to establish who was involved, whether privilege escalation was attempted and whether it succeeded, which permissions were abused, what happened after elevation, and what containment actions are required. Do not assume every IAM API call in the window is malicious.