Suspicious AWS SSM parameters retrieval activity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
SSM Remote Management Analytics
ATT&CK Tactic
Credential Access (TA0006), Collection (TA0009)
ATT&CK Technique
Unsecured Credentials (T1552), Data from Cloud Storage (T1530)
Severity
Informational
Description
An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.
Attacker's Goals
Collect secrets from the cloud environment.
Investigative actions
Check the accessed parameters' designation.
Verify that the identity did not dump any sensitive information that it shouldn't.
Variations
PreviousSuspicious authentication with Azure Password Hash Sync user
NextSuspicious Azure AD interactive sign-in using PowerShell
Was this helpful?
