Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0010 ✕ technique: T1071 ✕
Download CSV Show ATT&CK heatmapSuspicious Network Connection Originating from AWS SSM Agent Medium Cloud
A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)ATT&CK techniques: Application Layer Protocol (T1071) Exfiltration Over C2 Channel (T1041)Required data: XDR AgentDetector tags: SSM Remote Management AnalyticsAttacker's goals: Abuse the Amazon SSM agent to establish a covert command and control channel or exfiltrate data outside the cloud environment.Investigative actions: Verify the process spawned by SSM agent and validate its legitimacy. Inspect the destination IP and ASN in threat intelligence feeds. Review recent SSM document executions on the affected host.