Detection of SDK-Based AWS Control Plane Discovery from Suspicious Processes
This detection monitors for processes executing from temporary or user-writable directories that perform DNS queries to AWS management endpoints, a pattern frequently utilized by post-exploitation tools to bypass CLI-based security controls.
Malicious cloud-native post-exploitation tools frequently utilize AWS SDKs (such as boto3, aws-sdk-js, or the Go SDK) to perform reconnaissance and credential theft. Because these tools leverage libraries directly, they bypass traditional security rules that focus exclusively on monitoring the execution of the official AWS CLI binary. Defenders must instead monitor for the behavioral patterns of the calling processes. Specifically, attackers often stage their malicious scripts or binaries within temporary or user-writable directories (e.g., /tmp, /dev/shm, or AppData/Local/Temp) to maintain persistence or avoid detection. This threat brief covers the detection logic for identifying these suspicious processes when they exhibit network communication with AWS control plane endpoints such as AWS IAM, STS, SSM, Secrets Manager, and KMS. This monitoring approach is critical for identifying cloud environment discovery and credential abuse in environments where attackers use custom or off-the-shelf post-exploitation malware.
Impact
Successful exploitation allows attackers to perform comprehensive reconnaissance of cloud environments, harvest temporary or permanent credentials, and gain unauthorized access to managed resources. Attackers often escalate privileges, exfiltrate secrets, or gain persistent access to sensitive data within AWS workloads. Organizations in cloud-heavy sectors are particularly at risk, with observed incidents demonstrating full administrative access achieved in as little as eight minutes after initial compromise.
Recommendation
Detection engineering teams should implement monitoring for SDK-based cloud discovery to address the visibility gap left by CLI-name-based detection.
- Deploy the provided detection logic to monitor for processes originating from suspicious directories that resolve AWS control plane endpoints.
- Establish an exception process for CI/CD runners and legitimate build systems that operate in temporary directories to reduce noise.
- In the event of a high-confidence alert, cross-reference process activity with AWS CloudTrail logs to confirm unauthorized API usage.
- Isolate compromised hosts immediately upon detection and rotate all AWS credentials potentially harvested during the incident.
Immediate actions
Deploy process and network correlation logic to detect AWS SDK-based discovery from non-standard directories.
Threat Hunt
Search for DNS queries for aws.amazon.com endpoints originating from processes spawned in /tmp or AppData/Local/Temp.
Data: DNS query logs, Process creation telemetry