Analytics
Informational
✕
Suspicious AWS SSM parameters retrieval activity
An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Credential Access (TA0006) Collection (TA0009)
ATT&CK techniques: Unsecured Credentials (T1552) Data from Cloud Storage (T1530)
Detector tags: SSM Remote Management Analytics
Attacker's goals:
Collect secrets from the cloud environment.
Investigative actions:
Check the accessed parameters' designation. Verify that the identity did not dump any sensitive information that it shouldn't.
- Test period:
- 1 Hour
- Deduplication:
- 5 Days
1 variation:
- A non admin identity extracted multiple secrets within the organization across multiple regions Low (parent: Informational)