For the complete documentation index, see llms.txt. This page is also available as Markdown.

An identity started an AWS SSM session

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

3 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Lateral Movement Analytics, SSM Remote Management Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Direct Cloud VM Connections (T1021.008), Remote Services: Cloud Services (T1021.007)

Severity

Informational

Description

An identity started an AWS SSM interactive session.

Attacker's Goals

Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.

Investigative actions

  • Examine the specifics of the SSM session, including the source IP address, identity, and timestamp.

  • Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access.

  • Follow further actions taken by the identity or on the relevant instance.

Variations

An identity started an unusual AWS SSM session

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Direct Cloud VM Connections (T1021.008), Remote Services: Cloud Services (T1021.007)

Severity

Medium

Description

An identity started an AWS SSM interactive session.

Attacker's Goals

Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.

Investigative actions

  • Examine the specifics of the SSM session, including the source IP address, identity, and timestamp.

  • Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access.

  • Follow further actions taken by the identity or on the relevant instance.

An unusual identity started an AWS SSM session

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Direct Cloud VM Connections (T1021.008), Remote Services: Cloud Services (T1021.007)

Severity

Low

Description

An identity started an AWS SSM interactive session.

Attacker's Goals

Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.

Investigative actions

  • Examine the specifics of the SSM session, including the source IP address, identity, and timestamp.

  • Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access.

  • Follow further actions taken by the identity or on the relevant instance.

Was this helpful?