Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • AWS SSM association created with inventory collection document Informational Cloud 1 variation

    An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Execution (TA0002)
    ATT&CK techniques: Remote System Discovery (T1018) Cloud Administration Command (T1651)
    Required data: AWS Audit Log
    Detector tags: SSM Remote Management Analytics
    Attacker's goals: Enumerating managed hosts and installed software across the environment to identify targets for lateral movement or further exploitation.
    Investigative actions: Verify if the identity intended to create the SSM association. Examine the targets of the association to determine the scope of inventory collection. Follow further actions taken by the identity to detect potential lateral movement.

    Variations

    Unusual AWS SSM association created with inventory collection document

    Low overridden

    An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. overridden