AWS SSM parameters discovery
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
SSM Remote Management Analytics
ATT&CK Tactic
Credential Access (TA0006), Discovery (TA0007)
ATT&CK Technique
Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006), Cloud Service Discovery (T1526)
Severity
Informational
Description
An attempt was made to list parameters stored in AWS SSM.
Attacker's Goals
Exfiltrate sensitive secrets stored in SSM parameter store.
Investigative actions
Check if the secrets manager activity aligns with known workflows or automation, or if it indicates abnormal activity.
Follow further actions done by the identity.
Variations
PreviousAWS SSM association created with inventory collection document
NextAWS SSM parameters retrieval
Was this helpful?
