Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕
Download CSV Show ATT&CK heatmapEC2 backdoor created with newly added external SSH or RDP access High Cloud 1 variation
EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation (T1098)Required data: AWS Audit LogAttacker's goals: Create a reliable backdoor as an EC2 instance reachable from the attacker's IP address. Persistence relies on logging into the instance to obtain its instance-profile credentials and pivot into the AWS account. This requires the instance to be externally reachable over SSH or RDP and to have a public IP address.Investigative actions: Identify the instance profile used and which security groups were modified to allow external access. Analyze the identity that created the EC2 instance and instance profile, and any other actions it performed. Correlate with other suspicious activity from the instance profile or originating from the instance IP.Variations
EC2 backdoor created with a newly added external SSH or RDP access by a rarely used identity
High overridden
EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. overridden