AWS ChangePassword
Changes the calling IAM user’s console password.
The adversary is trying to manipulate, interrupt, or destroy your systems and data.
Impact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries’ goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.
In cloud environments, impact techniques include deleting critical resources (databases, storage, compute instances), encrypting data for ransom, modifying DNS records, or disrupting services by changing security configurations. Adversaries may also terminate instances, delete backups, or exhaust service quotas to cause denial of service.
View Impact on MITRE ATT&CK →Explore this tactic in the map.
Changes the calling IAM user’s console password.
Deletes an IAM access key permanently.
Deletes an empty S3 bucket, after all object versions and delete markers are removed.
Deletes an RDS DB cluster with configurable final-snapshot and backup handling.
Deletes an RDS DB instance with configurable final-snapshot and backup handling.
Deletes an EFS file system after mount-target and replication prerequisites are satisfied.
Deletes an empty Aurora global-database container after regional members are detached or deleted.
Deletes the target user’s AWS console password without deleting access keys.
Deletes an S3 object or a specified version, depending on versioning state.
Requests deletion of multiple S3 object keys or specific versions in one batch.
Deletes an EBS snapshot, subject to protection and retention controls.
Deletes an IAM user after dependent credentials and associations are removed.
Deletes an available EBS volume without deleting its snapshots.
Disables a KMS key for cryptographic operations until re-enabled.
Deletes a service account, potentially disrupting dependent workloads.
Deletes an Azure management lock.
Deletes an Azure RBAC role assignment.
Requests deletion of an Azure virtual machine.
Deletes an Event Hub entity within an Azure Event Hubs namespace.
Deletes an Azure Key Vault resource, subject to recovery and purge controls.
Deletes a named Key Vault secret and all its versions.
Deletes an Azure Log Analytics workspace, with optional permanent deletion.
Requests removal of protection and backup data for an Azure Backup protected item.
Deletes an Azure SQL Database while recovery depends on retained backups.
Deletes an Azure Blob Storage container through the management plane.
Deletes an Azure Storage account and makes its services unavailable.
Regenerates a selected Azure Storage account access key.
Creates or replaces S3 lifecycle rules for expiration and storage management.
Creates or replaces an S3 bucket lifecycle configuration.
Removes an IAM user from a group, changing the policies that apply to the user.
Schedules KMS key deletion and makes the pending key unavailable for cryptographic operations.
Deletes a Secret Manager secret and all its versions.
Destroys or schedules destruction of a Secret Manager secret version.
Deletes a Cloud Storage bucket, subject to contents and soft-delete policy.
Deletes a Cloud Storage object or a specified object generation.
Terminates EC2 instances, with storage impact determined by their configuration.
Sets an IAM access key to Active or Inactive.
Updates an IAM user console password or password-reset requirement.