Analytics Informational

AWS EC2 infrastructure enumeration activity

EC2 infrastructure enumeration activity detected within a specific AWS region.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Infrastructure Discovery (T1580)
Attacker's goals:

Discover EC2 resources and network setup to find potential weaknesses or targets. Use the gathered information to enable lateral movement, privilege escalation, or data exfiltration.

Investigative actions:

Identify and review the specific EC2 enumeration API calls executed and their frequency. Verify the identity performing the calls and assess if this behavior is typical or anomalous. Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.

Test period:
1 Hour
Deduplication:
1 Day