January 2024 (30)
AWS Account Compromise via New MFA Registration
2 rules 2 TTPsAn adversary may register a new Multi-Factor Authentication (MFA) method for an AWS account using the `CreateVirtualMFADevice` event in AWS CloudTrail logs to maintain persistence and evade detection in a compromised AWS account.
AWS Account Console Login Without MFA
2 rules 2 TTPsDetection of successful AWS console login events without multi-factor authentication (MFA) enabled, potentially indicating misconfiguration, policy violation, or account compromise.
AWS AMI Attribute Modification for Data Exfiltration
2 rules 1 TTPAn attacker modifies AWS AMI attributes, potentially sharing an AMI with another AWS account or making it publicly accessible, to exfiltrate sensitive data stored in AWS resources.
AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN
2 rules 1 TTPDetects successful AWS `AssumeRoleWithWebIdentity` calls where the caller identity is a Kubernetes service account and the source autonomous system organization is not `Amazon.com, Inc.`, which may indicate a stolen or misused projected service-account token being exchanged for IAM credentials off-cluster.
AWS Bedrock Invoke Model Access Denied Attempt
2 rules 2 TTPsDetection of AccessDenied errors when attempting to invoke AWS Bedrock models via the InvokeModel API indicates potential reconnaissance or privilege escalation attempts by an adversary with compromised credentials.
AWS Bedrock Model Invocation Logging Deletion Attempt
2 rules 1 TTPDetection of attempts to delete AWS Bedrock model invocation logging configurations, potentially indicating an adversary trying to remove audit trails of model interactions after credential compromise, to hide malicious AI model usage.
AWS CloudTrail Log Deletion for Defense Evasion
2 rules 1 TTPAn adversary deletes AWS CloudTrail logs to evade detection and operate stealthily within a compromised AWS environment, removing audit trails of their malicious activity.
AWS CloudTrail Logging Modification for Defense Evasion
2 rules 1 TTPAttackers modify AWS CloudTrail logging configurations to evade detection by disabling or altering logging, hindering security visibility and potentially allowing further malicious activities to go unnoticed.
AWS CloudTrail Logging Stopped for Defense Evasion
2 rules 1 TTP 1 IOCDetection of AWS CloudTrail `StopLogging` events indicating potential defense evasion by adversaries attempting to operate undetected within a compromised AWS environment by halting the logging of their malicious activities.
AWS CloudTrail Trail Creation Detected
2 rules 2 TTPsDetection of new AWS CloudTrail trail creation, potentially indicating malicious activity such as subverting monitoring objectives or capturing sensitive data by adversaries.
AWS CloudTrail UpdateTrail Defense Evasion
2 rules 1 TTPAn attacker modifies AWS CloudTrail configurations, specifically using the UpdateTrail API, to evade detection by impairing logging of their activities across multiple regions.
AWS CloudWatch Alarm Deletion for Defense Evasion
2 rules 2 TTPsSuccessful deletion of Amazon CloudWatch alarms via the `DeleteAlarms` API, potentially indicating an adversary attempting to impair visibility, silence alerts, and evade detection after malicious activity within an AWS environment.
AWS CloudWatch Log Group Deletion for Defense Evasion
2 rules 1 TTPThe deletion of AWS CloudWatch log groups, detected via CloudTrail logs, indicates a potential defense evasion attempt by adversaries aiming to remove audit trails and hinder incident response.
AWS CloudWatch Log Stream Deletion
2 rules 3 TTPsDetection of Amazon CloudWatch log stream deletion via the 'DeleteLogStream' API, potentially indicating defense evasion or impact by adversaries aiming to conceal activity and disrupt security monitoring.
AWS Console Login by New User
2 rules 1 TTPDetects first-time AWS console login, which can indicate compromised credentials or malicious account creation.
AWS Console Login by User from New Country
2 rules 1 TTPThis detection identifies AWS console logins by a user originating from a country not previously associated with that user, potentially indicating account compromise.
AWS Console Login Failed During MFA Challenge
2 rules 2 TTPsDetection of failed AWS console login attempts despite successful MFA usage, indicating potential account compromise attempts.
AWS Console Login from New City
2 rules 1 TTPA user logging into the AWS console from a previously unseen city could indicate compromised credentials or an insider threat.
AWS Credential Access via GetPasswordData API Abuse
2 rules 3 TTPsAn attacker attempts to retrieve encrypted administrator passwords for running Windows instances by abusing the AWS GetPasswordData API, potentially leading to full control over the affected instances.
AWS EC2 Instance Profile Associated with Running Instance
2 rules 2 TTPsAn attacker may escalate privileges by associating a compromised EC2 instance with a more privileged IAM instance profile.
AWS EC2 Snapshot Exfiltration Attempt
2 rules 1 TTPThis analytic detects potential exfiltration of data from AWS EC2 instances through the suspicious creation, modification, and deletion of EC2 snapshots within a short timeframe, potentially leading to unauthorized data access.
AWS EC2 Snapshot Shared Externally
2 rules 1 TTPDetection of AWS EC2 snapshot shared publicly, indicating potential data exfiltration, by analyzing AWS CloudTrail events.
AWS EC2 Stop, Start, and User Data Modification Correlation
3 rules 2 TTPsDetection of a sequence of AWS EC2 management API calls indicative of malicious modification of instance user data to execute arbitrary code upon instance restart, potentially leading to privilege escalation and persistence.
AWS ECR Container Scanning Reveals Medium Severity Vulnerabilities
2 rules 1 TTP 1 CVEAWS Elastic Container Registry (ECR) image scans reveal medium-severity vulnerabilities, potentially leading to unauthorized access and data breaches if exploited within containerized applications.
AWS ECR Container Upload Anomaly Outside Business Hours
2 rules 1 TTPThis detection identifies uploads of new containers to AWS Elastic Container Registry (ECR) outside of standard business hours, potentially indicating unauthorized access or malicious deployments.
AWS EFS File System Deletion Detected
2 rules 1 TTPAn adversary with sufficient permissions deletes an Amazon EFS file system using the 'DeleteFileSystem' API operation to destroy evidence, disrupt workloads, or impede recovery efforts.
AWS Excessive Security Scanning Detection
2 rules 1 TTPDetection of excessive AWS API calls indicative of reconnaissance by an attacker attempting to map an AWS environment.
AWS IAM AccessDenied Discovery Events
2 rules 1 TTPDetection of excessive AccessDenied events within an hour for AWS IAM users, indicating a potential compromised access key used for unauthorized discovery actions.
AWS IAM Account Concurrent Sessions from Multiple IPs
2 rules 1 TTPDetection of AWS IAM accounts exhibiting concurrent sessions originating from different IP addresses within a short timeframe, potentially indicating session hijacking.
AWS IAM API Calls via Temporary Session Tokens
3 rules 2 TTPsDetection of AWS IAM API operations using temporary session credentials, indicating potential credential theft, session hijacking, or privileged role abuse for persistence and defense evasion.