Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Zombie credentials in subsidiary clouds: what IAM teams need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A dormant IAM access key in subsidiary AWS infrastructure was used for reconnaissance, and Prophet says the investigation correlated unusual geography, a rare user agent, and behavioural mismatch across 6 data sources and 265 queries before the key was revoked. The case shows that visibility gaps, not just weak permissions, still let stale NHI credentials become live attack paths.

NHIMG editorial — based on content published by Prophet: Prophet AI in Action, unmasking zombie credentials in subsidiary infrastructure

By the numbers:

Questions worth separating out

Q: What breaks when dormant IAM keys are left in subsidiary environments?

A: Dormant IAM keys become standing attack paths when they are not tied to a current owner, rotation schedule, or retirement process.

Q: Why do stored NHI credentials increase cloud compromise impact?

A: Because the credential becomes a standing ticket into cloud services until it is rotated or revoked.

Q: How can security teams tell a compromised cloud identity from normal admin activity?

A: Look for context that does not fit the identity’s history, such as a new geography, a rare user agent, or API calls the identity has never made before.

Practitioner guidance

  • Audit dormant keys in subsidiary estates Review every non-production and subsidiary AWS account for access keys with no recent use, no named owner, or no current business justification.
  • Tie offboarding to credential retirement Make offboarding and environment decommissioning explicit triggers for key revocation, secret rotation, and account closure so that forgotten development identities do not remain valid indefinitely.
  • Alert on reconnaissance from unusual contexts Create detections for bucket enumeration, distribution discovery, and similar control-plane probing when the source geography, user agent, or session pattern has not been seen for that identity before.

What's in the full article

Prophet's full analysis covers the operational detail this post intentionally leaves for the source:

  • Step-by-step investigation logic for correlating a single GuardDuty alert with SIEM, cloud audit, and threat intelligence sources
  • The complete evidence chain behind the unusual geography, rare user agent, and behavioural mismatch verdict
  • The remediation sequence used to revoke the compromised key and clean up additional stale credentials in subsidiary infrastructure
  • How Prophet's query trace and reviewable evidence helped analysts validate the investigation outcome

👉 Read Prophet's analysis of zombie credentials in subsidiary infrastructure →

Zombie credentials in subsidiary clouds: what IAM teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Zombie credential risk is a lifecycle failure, not just a detection problem. The core issue is that an access key can remain valid long after the business relationship, owner, or use case has ended. That means NHI governance failed before the attacker arrived, because the identity lifecycle was never closed. Practitioners should treat stale credentials as evidence of incomplete offboarding, not merely weak monitoring.

A few things that frame the scale:

  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% confirmed and 26% suspected.

A question worth separating out:

Q: Who is accountable when stale access is not revoked?

A: Accountability sits with the identity governance owner, the application owner, and the access approver if the organisation has no clear offboarding or recertification path. Access control policy is only effective when revocation responsibilities are defined and measurable. Without that, stale access survives because no one is assigned to remove it.

👉 Read our full editorial: Zombie credentials in subsidiary clouds expose NHI governance gaps



   
ReplyQuote
Share: