Tobias Schmidt @tpschmidt.com · Jun 2

Root user logins in AWS should happen maybe once or twice in the life of an account. If you don't have an alert set up, you won't know when it does. Root access bypasses all IAM policies and SCPs. There's no way to restrict what it can do. Anyone who gets in as root owns the account, full stop.

1 likes 1 replies

?

Replies

Tobias Schmidt · Jun 2

Setting up an alert takes about 10 minutes with EventBridge. • Watch for ConsoleLogin events from aws.signin where userIdentity.type is Root • Route the event to a Lambda that publishes to SNS • Get an email the moment it happens