Suspicious Network Connection Originating from AWS SSM Agent
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Cloud
Detector Tags
SSM Remote Management Analytics
ATT&CK Tactic
Command and Control (TA0011), Exfiltration (TA0010)
ATT&CK Technique
Application Layer Protocol (T1071), Exfiltration Over C2 Channel (T1041)
Severity
Medium
Description
A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration.
Attacker's Goals
Abuse the Amazon SSM agent to establish a covert command and control channel or exfiltrate data outside the cloud environment.
Investigative actions
Verify the process spawned by SSM agent and validate its legitimacy.
Inspect the destination IP and ASN in threat intelligence feeds.
Review recent SSM document executions on the affected host.
Was this helpful?
