Analytics
Medium
✕
Cloud IMDS access followed by remote token usage
A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, XDR Agent
ATT&CK tactics: Initial Access (TA0001) Credential Access (TA0006)
ATT&CK techniques: Exploit Public-Facing Application (T1190) Unsecured Credentials (T1552)
Attacker's goals:
Gain unauthorized access by leveraging valid cloud credentials.
Investigative actions:
Identify the process that accessed the IMDS on the cloud instance. Examine the AWS API calls made by the stolen token, focusing on unusual or sensitive actions. Assess the role's permissions and rotate credentials if compromise is confirmed.
- Test period:
- 1 Hour
- Deduplication:
- 1 Hour