AWS Saml Update Identity Provider
This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker.
AWS Saml Update Identity Provider Help
You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs.
Open in Search