Product
Rapid Multi-Region AWS Service Quota Enumeration for EC2 vCPU Limits
2 rules 2 TTPsAn AWS principal rapidly enumerates EC2 on-demand vCPU service quotas across multiple regions, indicative of cloud infrastructure discovery for malicious purposes such as cryptocurrency mining or botnet hosting.
AWS EC2 Instance Console Login via Assumed Role
2 rules 5 TTPsAn AWS EC2 instance's assumed role is used to login to the AWS Management Console, potentially indicating credential theft and lateral movement.
Malicious Usage of AWS IMDS Credentials Outside of Expected Services
2 rules 3 TTPsCompromised EC2 instances may be leveraged to exfiltrate and misuse AWS Instance Metadata Service (IMDS) credentials to perform actions outside of the expected AWS Simple Systems Manager (SSM) service, indicating potential lateral movement or data exfiltration.
AWS EC2 Instance Connect SSH Public Key Upload
2 rules 3 TTPsThis rule detects the uploading of new SSH public keys to AWS EC2 instances using the EC2 Instance Connect service, which could indicate an adversary attempting to maintain access, escalate privileges, or move laterally within the cloud environment.
Insecure AWS EC2 VPC Security Group Ingress Rule Added
2 rules 2 TTPsAn AWS EC2 VPC security group ingress rule was added to allow traffic from any IP address (0.0.0.0/0 or ::/0) to common remote access ports, potentially exposing instances to unauthorized access and defense evasion.
AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role
2 rules 2 TTPsThe rule detects the first occurrence of an unauthorized attempt by an AWS role to use `GetPasswordData` to access the administrator password of an EC2 instance, potentially indicating privilege escalation or lateral movement.
AWS EC2 User Data Retrieval for EC2 Instance
2 rules 2 TTPsDetection of the AWS EC2 DescribeInstanceAttribute API call to retrieve the userData attribute, potentially exposing sensitive information like credentials or configuration details.
AWS VPC Flow Logs Deletion
2 rules 1 TTPAn adversary may delete flow logs in AWS EC2 using the DeleteFlowLogs API to evade defenses and hinder security monitoring, impacting incident response and log auditing capabilities.
AWS EC2 Route Table Created for Persistence or Defense Evasion
2 rules 2 TTPsAn EC2 Route Table creation event in AWS can indicate an attacker attempting to disrupt network traffic, reroute communications, or maintain persistence by creating unauthorized routes.
AWS EC2 EBS Snapshot Access Permissions Removed
2 rules 4 TTPsDetection of AWS EC2 EBS snapshot access permissions removal can indicate malicious attempts to disrupt data recovery, evade detection, or maintain exclusive backup access, leading to increased attack impact and incident response complexity.
AWS EC2 Route Table Modification or Deletion
2 rules 2 TTPsAn attacker modifies or deletes AWS EC2 route tables to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment.
Cloud Instance Modified by Previously Unseen User
2 rules 2 TTPsThis analytic identifies cloud instances being modified by users who have not previously modified them, specifically focusing on successful modifications of EC2 instances, potentially indicating unauthorized access and configuration changes.
Spike in AWS Security Hub Alerts for EC2 Instance
2 rules 6 TTPsDetects a sudden increase in security alerts generated by AWS Security Hub related to a specific EC2 instance, potentially indicating active compromise or misconfiguration.
Cloud Compute Instance Created With Previously Unseen Image
2 rules 2 TTPsThis analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.
AWS S3 Exfiltration Behavior Identified via Risk Correlation
2 rules 2 TTPsThis correlation identifies potential AWS S3 exfiltration behavior by correlating multiple risk events related to Collection and Exfiltration techniques, triggered when multiple analytics and distinct MITRE ATT&CK IDs are triggered for a specific risk object, indicating a potential data exfiltration attempt.
AWS EC2 Stop, Start, and User Data Modification Correlation
3 rules 2 TTPsDetection of a sequence of AWS EC2 management API calls indicative of malicious modification of instance user data to execute arbitrary code upon instance restart, potentially leading to privilege escalation and persistence.
AWS EC2 Snapshot Shared Externally
2 rules 1 TTPDetection of AWS EC2 snapshot shared publicly, indicating potential data exfiltration, by analyzing AWS CloudTrail events.
AWS EC2 Snapshot Exfiltration Attempt
2 rules 1 TTPThis analytic detects potential exfiltration of data from AWS EC2 instances through the suspicious creation, modification, and deletion of EC2 snapshots within a short timeframe, potentially leading to unauthorized data access.
AWS EC2 Instance Profile Associated with Running Instance
2 rules 2 TTPsAn attacker may escalate privileges by associating a compromised EC2 instance with a more privileged IAM instance profile.
AWS EC2 Instance Export for Potential Exfiltration
2 rules 5 TTPsAn attacker with compromised AWS credentials or EC2 instance access can leverage EC2 export functionalities (CreateInstanceExportTask, ExportImage, or CreateStoreImageTask) to exfiltrate sensitive data by exporting EC2 instances or their images to external storage.
Anomalous Cloud Compute Instance Creation by Unseen User
2 rules 1 TTPDetection of cloud compute instance creation by a user with no prior history of creating instances, potentially indicating unauthorized access, account compromise, or misuse of cloud resources leading to data exfiltration, increased costs, or further exploitation.
Unusual EC2 Instance Creation with Unseen Instance Type
2 rules 1 TTPAn attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.