Analytics Informational

Suspicious AWS SSM parameters retrieval activity

An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Credential Access (TA0006) Collection (TA0009)
ATT&CK techniques: Unsecured Credentials (T1552) Data from Cloud Storage (T1530)
Detector tags: SSM Remote Management Analytics
Attacker's goals:

Collect secrets from the cloud environment.

Investigative actions:

Check the accessed parameters' designation. Verify that the identity did not dump any sensitive information that it shouldn't.

Test period:
1 Hour
Deduplication:
5 Days
1 variation:
  • A non admin identity extracted multiple secrets within the organization across multiple regions Low (parent: Informational)