AWS EC2 infrastructure enumeration activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Cloud Infrastructure Discovery (T1580)
Severity
Informational
Description
EC2 infrastructure enumeration activity detected within a specific AWS region.
Attacker's Goals
Discover EC2 resources and network setup to find potential weaknesses or targets.
Use the gathered information to enable lateral movement, privilege escalation, or data exfiltration.
Investigative actions
Identify and review the specific EC2 enumeration API calls executed and their frequency.
Verify the identity performing the calls and assess if this behavior is typical or anomalous.
Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.
Was this helpful?
