Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • AWS Systems Manager hosts enumeration Informational Cloud 1 variation

    A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Cloud Infrastructure Discovery (T1580)
    Required data: AWS Audit Log
    Detector tags: SSM Remote Management Analytics
    Attacker's goals: Discover SSM managed instances to plan lateral movement, remote command execution, or further reconnaissance.
    Investigative actions: Determine whether the identity legitimately needs to enumerate SSM managed instances. Review subsequent activity by the identity, especially SSM SendCommand, StartSession, or instance profile modifications. Validate the source IP and user-agent of the API call.

    Variations

    AWS Systems Manager hosts enumeration via programmatic access

    Low overridden

    A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. overridden