Analytics BIOC Informational

An identity started an AWS SSM session

An identity started an AWS SSM interactive session.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Remote Services: Cloud Services (T1021.007)
Detector tags: Cloud Lateral Movement Analytics SSM Remote Management Analytics
Attacker's goals:

Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.

Investigative actions:

Examine the specifics of the SSM session, including the source IP address, identity, and timestamp. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant instance.

Test period:
N/A (single event)
Deduplication:
3 Days
2 variations:
  • An identity started an unusual AWS SSM session Medium (parent: Informational)
  • An unusual identity started an AWS SSM session Low (parent: Informational)