AWS resource drift from IaC configuration
Description
AlphaSOC detected modifications to AWS resources made outside the established infrastructure-as-code (IaC) workflow. These changes were identified through non-IaC user agents and bypassed version control, peer review, and automated deployment processes, creating discrepancies between the intended and actual infrastructure state. This activity may indicate manual interventions, emergency fixes, or unauthorized changes performed outside approved operational procedures. Threat actors can intentionally make changes outside the IaC workflow to exploit the infrastructure, introducing malicious configurations or backdoors that compromise security.
Impact
Changes made outside the IaC workflow can introduce security vulnerabilities, compliance violations, and operational instability. Configuration drift undermines infrastructure governance, complicates disaster recovery efforts, and increases the risk of service disruptions. Threat actors can exploit these inconsistencies to establish persistence, evade detection mechanisms, or execute malicious activities by leveraging unauthorized changes to the infrastructure.
Severity
| Severity | Condition |
|---|---|
Low | AWS resource drift from IaC configuration |