Analytics BIOC Low

A Command Line Interface (CLI) command was executed from an AWS serverless compute service

AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006) Execution (TA0002)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Steal Application Access Token (T1528) Unsecured Credentials (T1552) Command and Scripting Interpreter: Cloud API (T1059.009)
Detector tags: Cloud Serverless Function Credentials Theft Analytics
Attacker's goals:

Exfiltrate serverless token and abuse it.

Investigative actions:

Verify whether the serverless-attached identity's credentials were intentionally used in CLI. Check what CLI commands were executed using the serverless attached token. Check if the suspected serverless function is compromised.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • A Command Line Interface (AWS-CLI) command was executed from an AWS serverless compute service Informational (parent: Low)
  • Unusual Command Line Interface (CLI) command was executed from an AWS serverless compute service Low