Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1021 ✕

Download CSV Show ATT&CK heatmap
  • An identity started an AWS SSM session Informational Cloud 2 variations

    An identity started an AWS SSM interactive session.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    3 Days
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Remote Services: Cloud Services (T1021.007)
    Required data: AWS Audit Log
    Detector tags: Cloud Lateral Movement Analytics, SSM Remote Management Analytics
    Attacker's goals: Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.
    Investigative actions: Examine the specifics of the SSM session, including the source IP address, identity, and timestamp. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant instance.

    Variations

    An identity started an unusual AWS SSM session

    Medium overridden

    An identity started an AWS SSM interactive session. overridden

    An unusual identity started an AWS SSM session

    Low overridden

    An identity started an AWS SSM interactive session. overridden