AWS Secrets Manager bulk secret retrieval shortly after bastion host role assump
Detects high-velocity retrieval of multiple secrets from AWS Secrets Manager using a single IAM role or session shortly after activity initiation. This behavior is indicative of automated credential harvesting, often occurring post-compromise of a host (e.g., an SSH bastion) that has been assigned a high-privilege IAM role.
Microsoft Sentinel (KQL)

