For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS Systems Manager hosts enumeration

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

SSM Remote Management Analytics

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Infrastructure Discovery (T1580)

Severity

Informational

Description

A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution.

Attacker's Goals

Discover SSM managed instances to plan lateral movement, remote command execution, or further reconnaissance.

Investigative actions

  • Determine whether the identity legitimately needs to enumerate SSM managed instances.

  • Review subsequent activity by the identity, especially SSM SendCommand, StartSession, or instance profile modifications.

  • Validate the source IP and user-agent of the API call.

Variations

AWS Systems Manager hosts enumeration via programmatic access

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Infrastructure Discovery (T1580)

Severity

Low

Description

A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution.

Attacker's Goals

Discover SSM managed instances to plan lateral movement, remote command execution, or further reconnaissance.

Investigative actions

  • Determine whether the identity legitimately needs to enumerate SSM managed instances.

  • Review subsequent activity by the identity, especially SSM SendCommand, StartSession, or instance profile modifications.

  • Validate the source IP and user-agent of the API call.

Was this helpful?