Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • EC2 backdoor created with newly added external SSH or RDP access High Cloud 1 variation

    EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation (T1098)
    Required data: AWS Audit Log
    Attacker's goals: Create a reliable backdoor as an EC2 instance reachable from the attacker's IP address. Persistence relies on logging into the instance to obtain its instance-profile credentials and pivot into the AWS account. This requires the instance to be externally reachable over SSH or RDP and to have a public IP address.
    Investigative actions: Identify the instance profile used and which security groups were modified to allow external access. Analyze the identity that created the EC2 instance and instance profile, and any other actions it performed. Correlate with other suspicious activity from the instance profile or originating from the instance IP.

    Variations

    EC2 backdoor created with a newly added external SSH or RDP access by a rarely used identity

    High overridden

    EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. overridden