Skip to content
Threat Feed

Product

AWS Systems Manager

11 briefs RSS
high advisory

Detection of Unauthorized AWS EC2 GetPasswordData API Access

Adversaries may attempt to retrieve EC2 administrator passwords via the GetPasswordData API to facilitate privilege escalation or lateral movement within AWS environments.

AWS EC2 +3 aws cloud credential-access identity-and-access-audit incident-response ransomware persistence defense-evasion +4
5r 10t updated
medium advisory

Abuse of AWS Systems Manager Session Manager for Remote Execution

Adversaries abuse AWS Systems Manager (SSM) Session Manager to gain interactive shell access and perform remote command execution on EC2 instances or managed hybrid nodes.

AWS Systems Manager +1 cloud-security remote-execution lateral-movement cloud aws discovery reconnaissance
2r 5t updated
high advisory

Abuse of AWS Systems Manager for Remote LOLBin Execution

Adversaries are abusing the AWS Systems Manager SendCommand API to remotely execute commands on EC2 instances by leveraging legitimate system utilities (LOLBins) to bypass CloudTrail parameter redaction.

EC2 +2 cloud linux aws living-off-the-land execution command-and-control defense-evasion cloud-administration-command
1r 4t
medium advisory

Detection of Potential Credential Access via AWS SSM SecureString Decryption

This detection monitors for the first occurrence of an AWS identity accessing AWS Systems Manager (SSM) SecureString parameters with the decryption flag enabled, indicating potential unauthorized retrieval of stored sensitive credentials.

AWS Systems Manager credential-access cloud aws monitoring
1r 1t
high advisory

AWS SSM Command Document Created by Rare User

Adversaries may leverage AWS Systems Manager (SSM) command document creation by rare or unusual users to execute arbitrary commands on managed instances, potentially leading to unauthorized access, command and control, or data exfiltration.

AWS Systems Manager +1 cloud aws execution
1r 1t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule detects process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which can indicate remote execution and lateral movement by adversaries abusing legitimate AWS credentials.

AWS Systems Manager aws ssm execution cloud
3r 3t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule identifies process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which adversaries may abuse for remote execution and lateral movement using legitimate AWS credentials and IAM permissions.

AWS Systems Manager cloud aws execution lateral-movement
3r 3t
medium advisory

AWS Systems Manager SecureString Parameter Request with Decryption Flag

This rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true, potentially indicating credential access.

AWS Systems Manager aws credential-access cloud
2r 1t
medium advisory

AWS SSM Session Started to EC2 Instance for Lateral Movement

An AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.

AWS Systems Manager +1 aws lateral-movement ssm
2r 1t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
low advisory

AWS SSM `SendCommand` Execution by Rare User

This rule detects the execution of commands or scripts on EC2 instances using AWS Systems Manager (SSM) by an unexpected or new user, which could lead to malware installation, persistence, or reverse shell deployment.

AWS Systems Manager +1 aws ssm execution
2r 1t