Skip to content
Threat Feed

Product

AWS Systems Manager

7 briefs RSS
high advisory

AWS SSM Command Document Created by Rare User

Adversaries may leverage AWS Systems Manager (SSM) command document creation by rare or unusual users to execute arbitrary commands on managed instances, potentially leading to unauthorized access, command and control, or data exfiltration.

AWS Systems Manager +1 cloud aws execution
1r 1t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule detects process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which can indicate remote execution and lateral movement by adversaries abusing legitimate AWS credentials.

AWS Systems Manager aws ssm execution cloud
3r 3t
medium advisory

AWS SSM Session Manager Child Process Execution

This rule identifies process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which adversaries may abuse for remote execution and lateral movement using legitimate AWS credentials and IAM permissions.

AWS Systems Manager cloud aws execution lateral-movement
3r 3t
medium advisory

AWS Systems Manager SecureString Parameter Request with Decryption Flag

This rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true, potentially indicating credential access.

AWS Systems Manager aws credential-access cloud
2r 1t
medium advisory

AWS SSM Session Started to EC2 Instance for Lateral Movement

An AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.

AWS Systems Manager +1 aws lateral-movement ssm
2r 1t
medium threat

AWS SSM Inventory Reconnaissance by Rare User

Detection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.

AWS Systems Manager +1 Scattered Spider (LUCR-3) aws ssm inventory reconnaissance cloudtrail
2r 3t
low advisory

AWS SSM `SendCommand` Execution by Rare User

This rule detects the execution of commands or scripts on EC2 instances using AWS Systems Manager (SSM) by an unexpected or new user, which could lead to malware installation, persistence, or reverse shell deployment.

AWS Systems Manager +1 aws ssm execution
2r 1t