Product
Abuse of AWS EC2 Export APIs for Data Exfiltration
1 rule 2 TTPsAdversaries with compromised AWS credentials can exploit EC2 export APIs to copy entire virtual machine states or images to external storage for data exfiltration.
Detection of Unauthorized AWS EC2 GetPasswordData API Access
5 rules 10 TTPsAdversaries may attempt to retrieve EC2 administrator passwords via the GetPasswordData API to facilitate privilege escalation or lateral movement within AWS environments.
Generative Threat Groups Automating Cyber Operations with AI
3 TTPsAnthropic has documented multiple threat actors leveraging AI models to automate end-to-end cyberattack workflows including reconnaissance, vulnerability research, credential harvesting, and large-scale data exfiltration.
Monitoring Unauthorized AWS Security Group Modifications
1 rule 2 TTPsAdversaries modify AWS VPC security group ingress rules to permit unrestricted external access to sensitive management ports, facilitating remote access or future exploitation of cloud instances.
AWS EC2 Network ACL Deletion Defense Evasion
5 rules 9 TTPsAdversaries may delete AWS EC2 Network Access Control Lists (ACLs) or their ingress/egress entries to disable network-level security controls and facilitate unauthorized access or data exfiltration.
Detection of Unauthorized AWS Secrets Manager Credential Retrieval
1 rule 1 TTPAn adversary who has compromised an AWS service instance, such as EC2 or Lambda, may leverage assigned IAM roles to programmatically retrieve sensitive credentials from AWS Secrets Manager using the GetSecretValue API.
Detection of Unauthorized AWS NACL Modification by New Identities
1 TTPAdversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.
AWS EC2 AMI Shared with Another Account
1 rule 1 TTP 4 IOCsAdversaries with existing AWS access may exfiltrate sensitive data by sharing Amazon Machine Images (AMIs) containing secrets, bash histories, or code artifacts with external, attacker-controlled AWS accounts, detectable via `ModifyImageAttribute` actions in AWS CloudTrail logs.
AWS Bedrock API Key Phantom User Activity Outside Bedrock
1 rule 1 TTPAn Amazon Bedrock API key phantom user (IAM user starting with 'BedrockAPIKey-*') performing non-Bedrock API calls, such as to IAM, STS, EC2, VPC, or KMS, indicates credential misuse and realized privilege escalation by an attacker using added standard IAM access keys for reconnaissance or lateral movement beyond the intended Bedrock authentication boundary.
Detect AWS Route Table Modification via CloudTrail
2 rulesAn attacker may add a new route to an AWS route table, potentially redirecting network traffic for malicious purposes such as defense impairment or data exfiltration.
New AWS Network ACL Entry Creation Detected
2 rules 1 TTPDetection of new Network ACL entries in AWS CloudTrail logs can indicate potential defense impairment or the opening of new attack vectors within an AWS account by an adversary.
AWS EC2 AMI Shared with Another Account for Potential Exfiltration
2 rules 1 TTPAn AWS Amazon Machine Image (AMI) being shared with another AWS account could indicate data exfiltration, as AMIs may contain sensitive data, and unauthorized sharing can lead to exposure.
AWS SSM Session Started to EC2 Instance for Lateral Movement
2 rules 1 TTPAn AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.
AWS EC2 Network Access Control List Deletion
2 rules 1 TTPThe deletion of an Amazon EC2 network access control list (ACL) or its entries can indicate an attacker attempting to disable security controls for unauthorized access or data exfiltration.
Cloud Provisioning Activity From Previously Unseen City
2 rules 1 TTPThe analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.
AWS Credential Access via GetPasswordData API Abuse
2 rules 3 TTPsAn attacker attempts to retrieve encrypted administrator passwords for running Windows instances by abusing the AWS GetPasswordData API, potentially leading to full control over the affected instances.
AWS SSM Inventory Reconnaissance by Rare User
2 rules 3 TTPsDetection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.
AWS EC2 Serial Console Access Enabled
3 rules 2 TTPsThe EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer, which adversaries may enable for out-of-band communication, evading network-based security monitoring, firewalls, and VPC controls.