For the complete documentation index, see llms.txt. This page is also available as Markdown.

Suspicious Network Connection Originating from AWS SSM Agent

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detection Modules

Cloud

Detector Tags

SSM Remote Management Analytics

ATT&CK Tactic

Command and Control (TA0011), Exfiltration (TA0010)

ATT&CK Technique

Application Layer Protocol (T1071), Exfiltration Over C2 Channel (T1041)

Severity

Medium

Description

A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration.

Attacker's Goals

Abuse the Amazon SSM agent to establish a covert command and control channel or exfiltrate data outside the cloud environment.

Investigative actions

  • Verify the process spawned by SSM agent and validate its legitimacy.

  • Inspect the destination IP and ASN in threat intelligence feeds.

  • Review recent SSM document executions on the affected host.

Was this helpful?