From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
Unit 42 analyzes how AWS's AWSCompromisedKeyQuarantine managed policy automatically neutralizes exposed IAM access keys, plus monitoring strategies for quarantine events.
Palo Alto Unit 42 traces the evolution of the AWSCompromisedKeyQuarantine managed policy, created August 11, 2020 with V2 in April 2021 and V3 in August 2024, which AWS attaches automatically when IAM access keys are found exposed publicly. The article covers the GitHub secret scanning partner program, including validity checks and push protection, and walks through a real-world exposure test showing automatic quarantine. It closes with practical logging strategies for security teams to detect credential quarantine events for rapid incident response.