Detecting IAM persistence: attacker-created access keys
Creating a second access key on a compromised IAM user is one of the quietest persistence mechanisms in AWS. Here is what it looks like in CloudTrail, and a detection that survives contact with production.