A Command Line Interface (CLI) command was executed from an AWS serverless compute service
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Serverless Function Credentials Theft Analytics
ATT&CK Tactic
Initial Access (TA0001), Credential Access (TA0006), Execution (TA0002)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Steal Application Access Token (T1528), Unsecured Credentials (T1552), Command and Scripting Interpreter: Cloud API (T1059.009)
Severity
Low
Description
AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute.
Attacker's Goals
Exfiltrate serverless token and abuse it.
Investigative actions
Verify whether the serverless-attached identity's credentials were intentionally used in CLI.
Check what CLI commands were executed using the serverless attached token.
Check if the suspected serverless function is compromised.
Variations
Was this helpful?
