AWS Security Service Enumeration
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
15 Minutes
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Software Discovery (T1518), Software Discovery: Security Software Discovery (T1518.001), Cloud Infrastructure Discovery (T1580)
Severity
Informational
Description
AWS security service enumeration activity, potentially indicating reconnaissance.
Attacker's Goals
Reconnaissance of security defenses to assess and identify exploitable weaknesses.
Investigative actions
Review which API calls were executed and their frequency.
Analyze the identity performing the actions.
Inspect configurations of enumerated services.
Variations
PreviousAWS Security Group remote access allowed from an unknown external IP address
NextAWS SecurityHub findings were modified
Was this helpful?
