Command execution via AWS SSM
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
30 Minutes
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Execution (TA0002), Lateral Movement (TA0008)
ATT&CK Technique
Cloud Administration Command (T1651), Remote Services: Direct Cloud VM Connections (T1021.008)
Severity
Medium
Description
A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service.
Attacker's Goals
Gaining unauthorized access, executing unauthorized commands or compromising sensitive information within the target system.
Investigative actions
Investigate the activities related to the suspected identity.
Examine the code executed on the target instance(s).
Was this helpful?
