Analytics BIOC Informational

AWS SSM association created with inventory collection document

An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007) Execution (TA0002)
ATT&CK techniques: Remote System Discovery (T1018) Cloud Administration Command (T1651)
Detector tags: SSM Remote Management Analytics
Attacker's goals:

Enumerating managed hosts and installed software across the environment to identify targets for lateral movement or further exploitation.

Investigative actions:

Verify if the identity intended to create the SSM association. Examine the targets of the association to determine the scope of inventory collection. Follow further actions taken by the identity to detect potential lateral movement.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Unusual AWS SSM association created with inventory collection document Low (parent: Informational)