Skip to content
Threat Feed

Product

AWS EC2

11 briefs RSS
medium advisory

Detection of Unauthorized AWS NACL Modification by New Identities

Adversaries may modify AWS Network Access Control Lists (NACLs) to allow all traffic, effectively disabling network-layer defenses to facilitate lateral movement or data exfiltration, a behavior this detection identifies when performed by previously unseen identities.

AWS EC2 aws cloud defense-evasion
1t
high advisory

AWS Bedrock API Key Phantom User Activity Outside Bedrock

An Amazon Bedrock API key phantom user (IAM user starting with 'BedrockAPIKey-*') performing non-Bedrock API calls, such as to IAM, STS, EC2, VPC, or KMS, indicates credential misuse and realized privilege escalation by an attacker using added standard IAM access keys for reconnaissance or lateral movement beyond the intended Bedrock authentication boundary.

AWS Bedrock +5 cloud-security privilege-escalation aws bedrock iam
1r 1t
medium advisory

Detect AWS Route Table Modification via CloudTrail

An attacker may add a new route to an AWS route table, potentially redirecting network traffic for malicious purposes such as defense impairment or data exfiltration.

AWS EC2 +1 cloud aws network-routing
2r
low advisory

New AWS Network ACL Entry Creation Detected

Detection of new Network ACL entries in AWS CloudTrail logs can indicate potential defense impairment or the opening of new attack vectors within an AWS account by an adversary.

AWS CloudTrail +1 attack.defense-impairment attack.t1686.001 cloud
2r 1t
medium advisory

AWS EC2 AMI Shared with Another Account for Potential Exfiltration

An AWS Amazon Machine Image (AMI) being shared with another AWS account could indicate data exfiltration, as AMIs may contain sensitive data, and unauthorized sharing can lead to exposure.

AWS EC2 aws ami exfiltration
2r 1t
medium advisory

AWS SSM Session Started to EC2 Instance for Lateral Movement

An AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.

AWS Systems Manager +1 aws lateral-movement ssm
2r 1t
medium advisory

AWS EC2 Network Access Control List Deletion

The deletion of an Amazon EC2 network access control list (ACL) or its entries can indicate an attacker attempting to disable security controls for unauthorized access or data exfiltration.

AWS EC2 cloud aws ec2 network-security defense-evasion
2r 1t
medium advisory

Cloud Provisioning Activity From Previously Unseen City

The analytic detects cloud provisioning activities originating from previously unseen cities based on source IP geolocation compared to a learned baseline, which may indicate unauthorized access or misuse of cloud resources leading to resource creation, data exfiltration, or further compromise.

AWS +3 cloud anomaly-detection
2r 1t
critical advisory

AWS Credential Access via GetPasswordData API Abuse

An attacker attempts to retrieve encrypted administrator passwords for running Windows instances by abusing the AWS GetPasswordData API, potentially leading to full control over the affected instances.

AWS EC2 cloud aws credential-access ec2
2r 3t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
high advisory

AWS EC2 Serial Console Access Enabled

The EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer, which adversaries may enable for out-of-band communication, evading network-based security monitoring, firewalls, and VPC controls.

AWS EC2 aws cloudtrail defense-evasion ec2
3r 2t