heroui logo

AWS Route 53 Domain Transferred to Another Account

Elastic Detection Rules

View Source
Summary
The detection rule titled 'AWS Route 53 Domain Transferred to Another Account' serves to identify requests for transferring domains within AWS's Route 53 service to different AWS accounts. Such requests may be benign or could indicate potentially unauthorized access or manipulation of the account. The rule achieves this by monitoring specific AWS CloudTrail events, specifically targeting the event action 'TransferDomainToAnotherAwsAccount' with a successful outcome. This highlights potential misuse, such as unauthorized or suspicious transfers of domain ownership that could affect organizational control over domain resources. In the event of a detection, multiple avenues for investigation are suggested, including validating the identity of involved accounts and reviewing related AWS CloudTrail logs for unusual activity. Additionally, the rule provides mitigation steps in the case of an unauthorized transfer, emphasizing the importance of revoking improper access quickly and involving AWS support.
Categories
  • Cloud
Data Sources
  • Cloud Service
  • Network Traffic
  • Application Log
ATT&CK Techniques
  • T1098
Created: 2021-05-10