Analytics
High
✕
EC2 backdoor created with newly added external SSH or RDP access
EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation (T1098)
Attacker's goals:
Create a reliable backdoor as an EC2 instance reachable from the attacker's IP address. Persistence relies on logging into the instance to obtain its instance-profile credentials and pivot into the AWS account. This requires the instance to be externally reachable over SSH or RDP and to have a public IP address.
Investigative actions:
Identify the instance profile used and which security groups were modified to allow external access. Analyze the identity that created the EC2 instance and instance profile, and any other actions it performed. Correlate with other suspicious activity from the instance profile or originating from the instance IP.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- EC2 backdoor created with a newly added external SSH or RDP access by a rarely used identity High