Skip to content
Threat Feed

Product

AWS EC2

18 briefs RSS
medium advisory

Abuse of AWS EC2 Export APIs for Data Exfiltration

Adversaries with compromised AWS credentials can exploit EC2 export APIs to copy entire virtual machine states or images to external storage for data exfiltration.

Elastic Compute Cloud +1 cloud exfiltration collection aws
1r 2t updated
high advisory

Detection of Unauthorized AWS EC2 GetPasswordData API Access

Adversaries may attempt to retrieve EC2 administrator passwords via the GetPasswordData API to facilitate privilege escalation or lateral movement within AWS environments.

AWS EC2 +3 aws cloud credential-access identity-and-access-audit incident-response ransomware persistence defense-evasion +4
5r 10t updated
high advisory

Generative Threat Groups Automating Cyber Operations with AI

Anthropic has documented multiple threat actors leveraging AI models to automate end-to-end cyberattack workflows including reconnaissance, vulnerability research, credential harvesting, and large-scale data exfiltration.

AWS EC2 +2 ai-threat cyber-espionage surveillance reconnaissance data-exfiltration
3t
medium advisory

Monitoring Unauthorized AWS Security Group Modifications

Adversaries modify AWS VPC security group ingress rules to permit unrestricted external access to sensitive management ports, facilitating remote access or future exploitation of cloud instances.

EC2 +2
1r 2t updated
medium advisory

AWS EC2 Network ACL Deletion Defense Evasion

Adversaries may delete AWS EC2 Network Access Control Lists (ACLs) or their ingress/egress entries to disable network-level security controls and facilitate unauthorized access or data exfiltration.

AWS EC2 cloud defense-evasion aws discovery credential-access ebs encryption impact +1
5r 9t
medium advisory

Detection of Unauthorized AWS Secrets Manager Credential Retrieval

An adversary who has compromised an AWS service instance, such as EC2 or Lambda, may leverage assigned IAM roles to programmatically retrieve sensitive credentials from AWS Secrets Manager using the GetSecretValue API.

AWS Secrets Manager +2
1r 1t
medium advisory

Detection of Unauthorized AWS NACL Modification by New Identities

Adversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.

AWS EC2 aws cloud defense-evasion
1t
high advisory

AWS EC2 AMI Shared with Another Account

Adversaries with existing AWS access may exfiltrate sensitive data by sharing Amazon Machine Images (AMIs) containing secrets, bash histories, or code artifacts with external, attacker-controlled AWS accounts, detectable via `ModifyImageAttribute` actions in AWS CloudTrail logs.

Amazon EC2 +3 cloud aws exfiltration ami
1r 1t 4i updated
high advisory

AWS Bedrock API Key Phantom User Activity Outside Bedrock

An Amazon Bedrock API key phantom user (IAM user starting with 'BedrockAPIKey-*') performing non-Bedrock API calls, such as to IAM, STS, EC2, VPC, or KMS, indicates credential misuse and realized privilege escalation by an attacker using added standard IAM access keys for reconnaissance or lateral movement beyond the intended Bedrock authentication boundary.

AWS Bedrock +5 cloud-security privilege-escalation aws bedrock iam
1r 1t
medium advisory

Detect AWS Route Table Modification via CloudTrail

An attacker may add a new route to an AWS route table, potentially redirecting network traffic for malicious purposes such as defense impairment or data exfiltration.

AWS EC2 +1 cloud aws network-routing
2r
low advisory

New AWS Network ACL Entry Creation Detected

Detection of new Network ACL entries in AWS CloudTrail logs can indicate potential defense impairment or the opening of new attack vectors within an AWS account by an adversary.

AWS CloudTrail +1 attack.defense-impairment attack.t1686.001 cloud
2r 1t
medium advisory

AWS EC2 AMI Shared with Another Account for Potential Exfiltration

An AWS Amazon Machine Image (AMI) being shared with another AWS account could indicate data exfiltration, as AMIs may contain sensitive data, and unauthorized sharing can lead to exposure.

AWS EC2 aws ami exfiltration
2r 1t
medium advisory

AWS SSM Session Started to EC2 Instance for Lateral Movement

An AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.

AWS Systems Manager +1 aws lateral-movement ssm
2r 1t
medium advisory

AWS EC2 Network Access Control List Deletion

The deletion of an Amazon EC2 network access control list (ACL) or its entries can indicate an attacker attempting to disable security controls for unauthorized access or data exfiltration.

AWS EC2 cloud aws ec2 network-security defense-evasion
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen City

The analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.

AWS +3 cloud anomaly-detection
2r 1t
critical advisory

AWS Credential Access via GetPasswordData API Abuse

An attacker attempts to retrieve encrypted administrator passwords for running Windows instances by abusing the AWS GetPasswordData API, potentially leading to full control over the affected instances.

AWS EC2 cloud aws credential-access ec2
2r 3t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
high advisory

AWS EC2 Serial Console Access Enabled

The EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer, which adversaries may enable for out-of-band communication, evading network-based security monitoring, firewalls, and VPC controls.

AWS EC2 aws cloudtrail defense-evasion ec2
3r 2t