Detects the az or aws command-line tools enumerating cloud identities, roles and resources from a Windows endpoint (az account/ad user/role assignment list, aws sts get-caller-identity, aws iam list-users/roles). Post-compromise Cloud Service Discovery (ATT&CK T1526) via a stolen workstation's CLI session is an early step toward cloud pivot and privilege escalation. The rule matched on logsource `process_creation`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields — examine the exact value in the event:
Investigation queries (read-only):
Known benign causes for this rule:
The rule's references — CTI context to qualify the incident: