Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Suspicious Network Connection Originating from AWS SSM Agent Medium Cloud

    A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)
    ATT&CK techniques: Application Layer Protocol (T1071) Exfiltration Over C2 Channel (T1041)
    Required data: XDR Agent
    Detector tags: SSM Remote Management Analytics
    Attacker's goals: Abuse the Amazon SSM agent to establish a covert command and control channel or exfiltrate data outside the cloud environment.
    Investigative actions: Verify the process spawned by SSM agent and validate its legitimacy. Inspect the destination IP and ASN in threat intelligence feeds. Review recent SSM document executions on the affected host.