Product
high
advisory
AWS EC2 Instance Connect SSH Public Key Upload Detection
1 rule 3 TTPsAdversaries may upload SSH public keys to AWS EC2 instances via the EC2 Instance Connect service using the `SendSSHPublicKey` or `SendSerialConsoleSSHPublicKey` API actions, which can serve as a mechanism for initial access, persistence, or privilege escalation, particularly if the `SendSerialConsoleSSHPublicKey` action is coupled with unauthorized serial console access.
EC2 Instance Connect +1
cloud
aws
lateral-movement
privilege-escalation
persistence
1r
3t
medium
advisory
AWS EC2 Instance Connect SSH Public Key Upload
2 rules 3 TTPsThis rule detects the uploading of new SSH public keys to AWS EC2 instances using the EC2 Instance Connect service, which could indicate an adversary attempting to maintain access, escalate privileges, or move laterally within the cloud environment.
EC2 +1
cloud
aws
ssh
lateral-movement
privilege-escalation
persistence
2r
3t