Most Popular ShinyHunters 2026 Detection: AWS IAM Key Exposure via Compromised S
Detects anomalous AWS IAM and Secrets Manager API activity indicative of credential abuse following suspected exposure. The rule identifies suspicious patterns such as unauthorized enumeration of access keys, secret retrieval, and creation of new keys by non-service principals, reflecting activity associated with ShinyHunters-style operations where compromised credentials are abused.
Sigma

