For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS EC2 infrastructure enumeration activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Infrastructure Discovery (T1580)

Severity

Informational

Description

EC2 infrastructure enumeration activity detected within a specific AWS region.

Attacker's Goals

  • Discover EC2 resources and network setup to find potential weaknesses or targets.

  • Use the gathered information to enable lateral movement, privilege escalation, or data exfiltration.

Investigative actions

  • Identify and review the specific EC2 enumeration API calls executed and their frequency.

  • Verify the identity performing the calls and assess if this behavior is typical or anomalous.

  • Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.

Was this helpful?