Tag
Unusual AWS Batch Job Container Command Override Detection
1 rule 1 TTPThis detection targets the abuse of AWS Batch 'containerOverrides.command' parameters by infrequent users to inject malicious commands or data exfiltration logic into production compute environments.
AWS S3 Rapid Bucket Posture API Calls from a Single Principal
4 TTPsThis detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.
AWS Lambda Function Policy Updated to Allow Public Invocation
1 rule 2 TTPsAdversaries may modify AWS Lambda function policies via the AddPermission API call, setting the Principal to '*' to enable public invocation, which establishes persistence and creates a covert execution path within an AWS environment.
AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN
2 rules 1 TTPDetects successful AWS AssumeRoleWithWebIdentity where the caller identity is a Kubernetes service account and the source autonomous system organization is not Amazon.com, Inc., potentially indicating a stolen or misused service-account token being used off-cluster.
Rapid Enumeration of AWS S3 Buckets
2 rules 4 TTPsAn AWS principal rapidly enumerates S3 bucket posture using read-only APIs, indicative of reconnaissance, scanning, or post-compromise activity.
AWS Discovery API Calls via CLI from a Single Resource
2 rules 2 TTPsThis rule detects when a single AWS identity executes more than five unique discovery-related API calls (Describe*, List*, Get*, or Generate*) within a 10-second window using the AWS CLI, potentially indicating reconnaissance activity following credential compromise or compromised EC2 instance access.
Suspicious AWS EC2 Key Pair Import Activity
2 rules 1 TTPThe import of SSH key pairs into AWS EC2, as detected by CloudTrail logs, may indicate unauthorized access attempts, persistence establishment, or privilege escalation by an attacker.
AWS SAML Provider Deletion Activity
2 rules 2 TTPsAn adversary may delete an AWS SAML provider to disrupt administrative access, hindering incident response and potentially escalating privileges within the AWS environment.
AWS S3 Unauthenticated Bucket Access by Rare Source
2 rules 4 TTPsThis rule detects AWS CloudTrail events indicative of unauthenticated sources attempting to access an S3 bucket, potentially exposing sensitive data due to misconfigured bucket policies.
AWS Discovery API Calls via CLI from a Single Resource
2 rules 3 TTPsA single AWS resource is making multiple read-only discovery API calls via the AWS CLI within a 10-second window, indicating potential reconnaissance attempts using compromised credentials or a compromised instance.
AWS STS AssumeRole with New MFA Device
2 rules 4 TTPsThis rule identifies when a user has assumed a role using a new MFA device in AWS, which can be indicative of persistence and privilege escalation attempts by threat actors.
AWS EC2 Instance Console Login via Assumed Role
2 rules 5 TTPsAn AWS EC2 instance's assumed role is used to login to the AWS Management Console, potentially indicating credential theft and lateral movement.
AWS Federated User Console Login without MFA Enforcement
2 rules 1 TTPDetection of successful AWS Management Console logins by federated users, which pose a security risk due to potential lack of enforced MFA as CloudTrail does not reliably record MFA status for federated users.
AWS S3 Bucket Replicated to Another Account
2 rules 2 TTPsDetection of S3 bucket replication configurations sending data to a different AWS account, potentially indicating unauthorized data exfiltration by adversaries abusing replication rules.
AWS Bedrock Model Invocation Logging Deletion
2 rules 1 TTPDetection of AWS Bedrock model invocation logging configuration deletion via the DeleteModelInvocationLogging API in CloudTrail logs, potentially indicating an adversary attempting to evade detection of malicious AI model usage.
AWS Route 53 Resolver Query Log Configuration Deleted
2 rules 1 TTPDetection of the deletion of an Amazon Route 53 Resolver Query Log Configuration, potentially stopping DNS query and response logging for associated VPCs, which can be used by adversaries to evade detection and suppress forensic evidence.
AWS EC2 User Data Retrieval for EC2 Instance
2 rules 2 TTPsDetection of the AWS EC2 DescribeInstanceAttribute API call to retrieve the userData attribute, potentially exposing sensitive information like credentials or configuration details.
AWS VPC Flow Logs Deletion
2 rules 1 TTPAn adversary may delete flow logs in AWS EC2 using the DeleteFlowLogs API to evade defenses and hinder security monitoring, impacting incident response and log auditing capabilities.
AWS Root Account Password Recovery Request Detection
2 rules 1 TTPDetection of AWS root account password recovery requests, potentially indicating unauthorized access attempts or legitimate administrative actions requiring verification.
AWS Identity API Access from Rare ASN Organizations
2 rules 1 TTPThis rule detects AWS identities with API traffic dominated by cloud-provider source AS organization labels, but also exhibit traffic from other AS organizations, potentially indicating credential reuse or pivoting.
AWS S3 Data Exfiltration via Uncommon Clients
2 rules 1 TTPDetection of AWS API activity from rare S3 client applications (S3 Browser, Cyberduck), potentially indicating unauthorized data exfiltration by threat actors.
S3Browser IAM Policy Creation with Default Bucket Name
2 rules 3 TTPsAn AWS IAM policy is created by the S3Browser utility with the default S3 bucket name placeholder, potentially indicating unauthorized access or misconfiguration.
AWS EBS Encryption Disabled
2 rules 2 TTPsDetects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region, potentially leading to data exposure and weakening data protection against exfiltration or ransomware.
Rapid Enumeration of AWS S3 Buckets via API Calls
2 rules 4 TTPsAn AWS principal from a single source IP rapidly invokes read-only S3 control-plane APIs, revealing bucket posture across many buckets in a short time, potentially indicating automated reconnaissance or post-compromise enumeration.
Successful AWS Console Login Without MFA
2 rules 1 TTPSuccessful AWS console logins without multi-factor authentication can indicate compromised credentials, misconfigured security settings, or unauthorized access attempts.
AWS IAM Long-Term Access Key First Seen from Source IP
2 rules 2 TTPsThe rule identifies the first time a long-term IAM access key ID (prefix AKIA) is used successfully from a given source.ip in AWS CloudTrail, indicating potential credential compromise.
AWS EC2 Route Table Modification or Deletion
2 rules 2 TTPsAn attacker modifies or deletes AWS EC2 route tables to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment.
AWS CloudTrail Trail Update Detection
2 rules 3 TTPsDetection of AWS CloudTrail trail updates via the UpdateTrail API, potentially indicating malicious attempts to reduce logging visibility, change log destinations, or weaken log integrity, enabling adversaries to evade detection.
AWS CloudTrail Logging Suspended via StopLogging API
3 rules 2 TTPsAn attacker may suspend AWS CloudTrail logging via the StopLogging API (StopLogging) to eliminate audit visibility and evade defenses.
AWS CloudTrail Trail Deletion Detected
2 rules 2 TTPsDetection of AWS CloudTrail trail deletion via the DeleteTrail API indicates potential defense evasion and destruction of audit logging.
Suspicious AWS SAML Activity Detection
2 rules 3 TTPsThis rule identifies suspicious SAML activity in AWS, such as AssumeRoleWithSAML and UpdateSAMLProvider events, which could indicate an attacker gaining backdoor access, escalating privileges, or establishing persistence.
AWS RDS Snapshot Export to S3 for Potential Data Exfiltration
2 rules 1 TTPAn adversary may export RDS snapshots to Amazon S3 to exfiltrate sensitive data outside of RDS-managed storage, potentially bypassing database access controls and leading to unauthorized data theft.
AWS GuardDuty Detector Deletion or Disablement
3 rulesAttackers may delete or disable AWS GuardDuty detectors to impair defenses and evade detection of malicious activities within the AWS environment.
AWS Bedrock Knowledge Base Deletion Attempt
2 rules 2 TTPsAn adversary may delete AWS Bedrock Knowledge Bases, which are resources that store and manage domain-specific information for AI models, to disrupt business operations or remove traces of data access by using the DeleteKnowledgeBase API call.
AWS User Login Profile Update by Different User
2 rules 1 TTPA user updating the login profile of another user in AWS CloudTrail logs may indicate privilege escalation attempts.
AWS Data Exfiltration via DataSync Task Creation
2 rules 1 TTPAn attacker may create an AWS DataSync task to exfiltrate data from a private AWS location to a public one, leading to data compromise, detected by monitoring AWS CloudTrail logs for the `CreateTask` event from the DataSync service.
AWS CloudTrail Stop Logging Detection
2 rules 1 TTPDetection of adversaries stopping CloudTrail logging to evade detection and operate stealthily within a compromised AWS environment.
Cloud Provisioning Activity From Previously Unseen IP Address
2 rules 1 TTPThis analytic detects cloud provisioning activities originating from previously unseen IP addresses by leveraging cloud infrastructure logs to identify events where resources are created or started, and cross-references these with a baseline of known IP addresses.
Cloud Compute Instance Created With Previously Unseen Image
2 rules 2 TTPsThis analytic detects the creation of cloud compute instances using previously unseen image IDs, potentially indicating unauthorized or suspicious activity like malicious payload deployment or unauthorized access, leading to data breaches or further cloud environment compromise.
AWS Security Services Impairment via Deletion Operations
3 rules 1 TTPAttackers attempt to impair or disable AWS security services such as GuardDuty, WAF, CloudWatch, Route 53 and CloudWatch Logs by deleting detectors, rule groups, IP sets, web ACLs, logging configurations, alarms and log streams, in order to evade detection and operate undetected.
AWS Security Services Impairment via Deletion of Resources
2 rules 1 TTPDetection of adversaries attempting to impair or disable AWS security services by deleting resources across GuardDuty, AWS WAF, CloudWatch, Route 53, and CloudWatch Logs to evade detection and remove visibility.
AWS Security Services Configuration Deletion
2 rules 1 TTPDetection of deletion of critical AWS Security Services configurations like CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules to evade detection, potentially leading to data breaches and unauthorized access.
AWS Network ACL Deletion Detection
2 rules 1 TTPDetection of AWS Network Access Control List (ACL) deletion via CloudTrail logs, potentially indicating malicious attempts to bypass network security controls and gain unauthorized access.
AWS Network Access Control List Deletion Detected
3 rules 1 TTPDetection of AWS Network Access Control List (ACL) deletion events via CloudTrail logs indicates a potential attempt to weaken network security controls.
AWS Multi-Factor Authentication Disabled
2 rules 3 TTPsDetection of AWS Multi-Factor Authentication (MFA) being disabled for an IAM user, indicating potential weakening of account security and persistence attempts.
AWS Management Console Failed Login Attempts
2 rules 2 TTPsDetection of repeated failed login attempts to the AWS Management Console, potentially indicating brute-force or credential access attempts by threat actors aiming to compromise AWS accounts.
AWS IAM Session Token Used From Multiple Addresses
2 rules 1 TTPCompromised AWS IAM session tokens are used from multiple IP addresses, networks, cities, and user agents within a short timeframe, indicating potential credential theft and abuse.
AWS IAM Policy Version Created Allowing Access to All Resources
2 rules 1 TTPAn AWS IAM policy version allowing access to all resources has been created, potentially leading to privilege escalation and unauthorized actions.
AWS IAM Policy Deletion Detection
2 rules 1 TTPDetection of AWS IAM policy deletion events, which could indicate malicious activity by a compromised account or insider threat.
AWS IAM MFA Device Deactivation
2 rules 3 TTPsDetection of AWS IAM MFA device deactivation via the `DeactivateMFADevice` API call, which could indicate an attempt to weaken account protections for privilege escalation or persistence.
AWS IAM AccessDenied Discovery Events
2 rules 1 TTPDetection of excessive AccessDenied events within an hour for AWS IAM users, indicating a potential compromised access key used for unauthorized discovery actions.
AWS Excessive Security Scanning Detection
2 rules 1 TTPDetection of excessive AWS API calls indicative of reconnaissance by an attacker attempting to map an AWS environment.
AWS EC2 Snapshot Shared Externally
2 rules 1 TTPDetection of AWS EC2 snapshot shared publicly, indicating potential data exfiltration, by analyzing AWS CloudTrail events.
AWS EC2 Snapshot Exfiltration Attempt
2 rules 1 TTPThis analytic detects potential exfiltration of data from AWS EC2 instances through the suspicious creation, modification, and deletion of EC2 snapshots within a short timeframe, potentially leading to unauthorized data access.
AWS CloudTrail UpdateTrail Defense Evasion
2 rules 1 TTPAn attacker modifies AWS CloudTrail configurations, specifically using the UpdateTrail API, to evade detection by impairing logging of their activities across multiple regions.
AWS CloudTrail Trail Creation Detected
2 rules 2 TTPsDetection of new AWS CloudTrail trail creation, potentially indicating malicious activity such as subverting monitoring objectives or capturing sensitive data by adversaries.
AWS CloudTrail Logging Stopped for Defense Evasion
2 rules 1 TTP 1 IOCDetection of AWS CloudTrail `StopLogging` events indicating potential defense evasion by adversaries attempting to operate undetected within a compromised AWS environment by halting the logging of their malicious activities.
AWS CloudTrail Logging Modification for Defense Evasion
2 rules 1 TTPAttackers modify AWS CloudTrail logging configurations to evade detection by disabling or altering logging, hindering security visibility and potentially allowing further malicious activities to go unnoticed.
AWS CloudTrail Log Deletion for Defense Evasion
2 rules 1 TTPAn adversary deletes AWS CloudTrail logs to evade detection and operate stealthily within a compromised AWS environment, removing audit trails of their malicious activity.
AWS Bedrock Model Invocation Logging Deletion Attempt
2 rules 1 TTPDetection of attempts to delete AWS Bedrock model invocation logging configurations, potentially indicating an adversary trying to remove audit trails of model interactions after credential compromise, to hide malicious AI model usage.
AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN
2 rules 1 TTPDetects successful AWS `AssumeRoleWithWebIdentity` calls where the caller identity is a Kubernetes service account and the source autonomous system organization is not `Amazon.com, Inc.`, which may indicate a stolen or misused projected service-account token being exchanged for IAM credentials off-cluster.
AWS AMI Attribute Modification for Data Exfiltration
2 rules 1 TTPAn attacker modifies AWS AMI attributes, potentially sharing an AMI with another AWS account or making it publicly accessible, to exfiltrate sensitive data stored in AWS resources.
AWS Account Compromise via New MFA Registration
2 rules 2 TTPsAn adversary may register a new Multi-Factor Authentication (MFA) method for an AWS account using the `CreateVirtualMFADevice` event in AWS CloudTrail logs to maintain persistence and evade detection in a compromised AWS account.
Detection of Public AWS S3 Bucket Creation via CLI
2 rules 1 TTPAn AWS user creates a publicly accessible S3 bucket by using the AWS CLI to set permissive ACLs, potentially leading to unauthorized data access and data breaches.
AWS Suspicious User Agent Detected in CloudTrail
2 rules 2 TTPsSuccessful AWS API calls with CloudTrail user agents indicating offensive tooling (Kali Linux) or credential verification (TruffleHog) can indicate compromised credentials or unauthorized access.
AWS S3 Bucket Lifecycle Rule Abuse for Log Deletion
2 rules 1 TTPAttackers may abuse the AWS S3 PutBucketLifecycle API to rapidly delete CloudTrail logs by setting short expiration periods on S3 buckets, hindering incident response and forensic investigations.
AWS High Number of Failed Console Login Attempts
2 rules 2 TTPsAn IP address exhibiting more than 20 failed AWS console login attempts within a 5-minute window, indicative of potential brute-force or password spraying attacks against AWS accounts.
AWS Console Login Password Spraying
2 rules 3 TTPsA single source IP failing to authenticate into the AWS Console with multiple valid users, potentially indicating a password spraying attack against cloud resources.
High Number of AWS Bedrock List Foundation Model Failures
2 rules 1 TTPDetection of a high number of AccessDenied errors when attempting to list AWS Bedrock foundation models, indicating potential reconnaissance activity after credential compromise to discover accessible AI models.
AWS EC2 Instance Export for Potential Exfiltration
2 rules 5 TTPsAn attacker with compromised AWS credentials or EC2 instance access can leverage EC2 export functionalities (CreateInstanceExportTask, ExportImage, or CreateStoreImageTask) to exfiltrate sensitive data by exporting EC2 instances or their images to external storage.
AWS SSM Inventory Reconnaissance by Rare User
2 rules 3 TTPsDetection of a rare user or role accessing AWS Systems Manager (SSM) inventory APIs or running the AWS-GatherSoftwareInventory job, potentially indicating reconnaissance activity by threat actors seeking information about managed EC2 instances.
AWS S3 Data Exfiltration via Uncommon Client Applications
3 rules 2 TTPsThis rule detects AWS API activity originating from uncommon desktop client applications based on the user agent string, specifically S3 Browser and Cyberduck, which provide bulk upload/download capabilities and have been observed in use by threat actors for data exfiltration, warranting validation against authorized data transfer workflows.
AWS S3 Bucket Lifecycle Rule for Rapid Log Deletion
2 rules 1 TTPAn attacker modifies an AWS S3 bucket lifecycle policy to rapidly expire CloudTrail logs, hindering incident response and forensic analysis.
AWS IAM Group Deletion Detected
2 rules 1 TTPDetection of AWS IAM group deletion via the DeleteGroup API call, which may indicate an attacker removing audit trails, disrupting operations, or concealing privileged access activity.
AWS EC2 Serial Console Access Enabled
3 rules 2 TTPsThe EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer, which adversaries may enable for out-of-band communication, evading network-based security monitoring, firewalls, and VPC controls.
AWS DynamoDB Scan by Unusual User
2 rules 3 TTPsDetection of unusual DynamoDB scan activity in AWS environments, potentially indicating exfiltration of sensitive information by an adversary using compromised credentials or a rogue insider.
AWS Credential Access via GetPasswordData API Calls
2 rules 3 TTPsDetection of anomalous GetPasswordData API calls in AWS CloudTrail logs, indicating potential attempts to retrieve encrypted administrator passwords for Windows instances, leading to unauthorized access.
AWS Config Configuration Recorder Stopped
2 rules 2 TTPsDetection of AWS Config configuration recorder being stopped, potentially by an adversary to evade detection and obscure activity.
AWS CloudTrail Logging Evasion via Oversized IAM Policies
2 rules 1 TTPAttackers evade AWS CloudTrail logging by padding IAM policy documents with whitespace, exceeding logging size limits and obscuring unauthorized changes to IAM policies.
AWS Bedrock GuardRails Deletion Attempt
2 rules 1 TTPDetection of AWS Bedrock GuardRails deletion, which are security controls to prevent harmful AI outputs, could indicate an adversary attempting to remove safety measures after credential compromise to enable malicious model outputs.
AWS IAM Assume Role Policy Brute Force Attack
1 rule 2 TTPsDetection of brute force attacks against AWS IAM roles by identifying multiple failed AssumeRole attempts using CloudTrail logs, potentially leading to unauthorized access and resource compromise.