Analytics BIOC
Low
✕
A Command Line Interface (CLI) command was executed from an AWS serverless compute service
AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006) Execution (TA0002)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Steal Application Access Token (T1528) Unsecured Credentials (T1552) Command and Scripting Interpreter: Cloud API (T1059.009)
Detector tags: Cloud Serverless Function Credentials Theft Analytics
Attacker's goals:
Exfiltrate serverless token and abuse it.
Investigative actions:
Verify whether the serverless-attached identity's credentials were intentionally used in CLI. Check what CLI commands were executed using the serverless attached token. Check if the suspected serverless function is compromised.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
2 variations:
- A Command Line Interface (AWS-CLI) command was executed from an AWS serverless compute service Informational (parent: Low)
- Unusual Command Line Interface (CLI) command was executed from an AWS serverless compute service Low