Analytics Medium

Command execution via AWS SSM

A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Execution (TA0002) Lateral Movement (TA0008)
ATT&CK techniques: Cloud Administration Command (T1651) Remote Services: Direct Cloud VM Connections (T1021.008)
Attacker's goals:

Gaining unauthorized access, executing unauthorized commands or compromising sensitive information within the target system.

Investigative actions:

Investigate the activities related to the suspected identity. Examine the code executed on the target instance(s).

Test period:
30 Minutes
Deduplication:
1 Day