Product
AWS SSM Command Document Created by Rare User
1 rule 1 TTPAdversaries may leverage AWS Systems Manager (SSM) command document creation by rare or unusual users to execute arbitrary commands on managed instances, potentially leading to unauthorized access, command and control, or data exfiltration.
AWS SSM Session Manager Child Process Execution
3 rules 3 TTPsThis rule detects process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which can indicate remote execution and lateral movement by adversaries abusing legitimate AWS credentials.
AWS SSM Session Manager Child Process Execution
3 rules 3 TTPsThis rule identifies process start events where the parent process is the AWS Systems Manager (SSM) Session Manager worker, which adversaries may abuse for remote execution and lateral movement using legitimate AWS credentials and IAM permissions.
AWS Systems Manager SecureString Parameter Request with Decryption Flag
2 rules 1 TTPThis rule detects when an AWS resource accesses SecureString parameters within AWS Systems Manager (SSM) with the decryption flag set to true, potentially indicating credential access.
AWS SSM Session Started to EC2 Instance for Lateral Movement
2 rules 1 TTPAn AWS user or role establishing a session via SSM to an EC2 instance may indicate lateral movement, and this rule detects the first occurrence of such an event.
AWS SSM Inventory Reconnaissance by Rare User
2 rules 3 TTPsDetection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.
AWS SSM `SendCommand` Execution by Rare User
2 rules 1 TTPThis rule detects the execution of commands or scripts on EC2 instances using AWS Systems Manager (SSM) by an unexpected or new user, which could lead to malware installation, persistence, or reverse shell deployment.