AWS Saml Update Identity Provider

Description

This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker.

   Help

AWS Saml Update Identity Provider Help

You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs.

   Search

Open in Search