Autonomous Hunter

3,625 KMS calls. One admin role.

3,625
KMS calls tied to a single admin role
6–160
Baseline, normal KMS Decrypt calls per day
3,625
Spike, calls in 2 hours, Z-score 573
59
Lambda functions, all running under federation/AdminRole
375
Severity score, one of the highest in the environment

The problem

A 50x spike in KMS Decrypt calls looked exactly like credential exfiltration.

A 50x spike in KMS Decrypt calls, Z-score of 573, was traced to 59 Lambda functions running with full administrative privileges.

Indistinguishable from attack

An elevated service role combined with high-volume KMS Decrypt calls is identical to a post-compromise credential exfiltration pattern. Detecting this requires understanding what's normal for each service, not just what looks bad in isolation.

Full decomposition

All 59 Lambda functions were mapped to their owning teams. Each made exactly 61 KMS calls. Systematic, not random.

The finding

A developer elevated privileges for testing and never reverted. Production Lambda functions running as admin is a real least-privilege violation, not a false positive, delivered as a concrete remediation target with full context.

Contact us for a 30-day POV
on your own cloud environment.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai