AWS Systems Manager hosts enumeration
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
SSM Remote Management Analytics
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Cloud Infrastructure Discovery (T1580)
Severity
Informational
Description
A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution.
Attacker's Goals
Discover SSM managed instances to plan lateral movement, remote command execution, or further reconnaissance.
Investigative actions
Determine whether the identity legitimately needs to enumerate SSM managed instances.
Review subsequent activity by the identity, especially SSM SendCommand, StartSession, or instance profile modifications.
Validate the source IP and user-agent of the API call.
Variations
Was this helpful?
