AWS IAM Access Key Creation Followed by API Use from New IP
Detects instances where an IAM user creates a new access key or requests a session token, followed by subsequent API activity from a different source IP address or region within a one-hour window. This behavior is often associated with the creation of persistence mechanisms or credential theft.
YARA-L

