Analytics BIOC
Informational
✕
AWS SSM send command attempt
An identity executed an AWS SSM Document.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Cloud Administration Command (T1651)
Detector tags: Cloud Lateral Movement Analytics SSM Remote Management Analytics
Attacker's goals:
Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.
Investigative actions:
Examine the code in the SSM document, and the target objects. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant targets.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Days
2 variations:
- AWS SSM SendCommand targeting multiple instances Low (parent: Informational)
- Unusual AWS SSM send command Low (parent: Informational)