AWS SSM association created with inventory collection document
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
SSM Remote Management Analytics
ATT&CK Tactic
Discovery (TA0007), Execution (TA0002)
ATT&CK Technique
Remote System Discovery (T1018), Cloud Administration Command (T1651)
Severity
Informational
Description
An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration.
Attacker's Goals
Enumerating managed hosts and installed software across the environment to identify targets for lateral movement or further exploitation.
Investigative actions
Verify if the identity intended to create the SSM association.
Examine the targets of the association to determine the scope of inventory collection.
Follow further actions taken by the identity to detect potential lateral movement.
Variations
Was this helpful?
