NorthLedger has detected unauthorised activity within its AWS environment after several high-cost EC2 instances were launched without approval.
Initial evidence suggests that credentials belonging to the svc-deploy IAM user were compromised. The attacker appears to have enumerated the environment, created a new administrative user, disabled security controls and accessed sensitive data stored in S3.
Although the primary CloudTrail trail was stopped, additional activity was recovered from CloudTrail Event History and other available logging sources.
Your task is to analyse the recovered events, identify the compromised account and reconstruct the attack timeline.
Please note use index=aws to find the relevant data.
