Analytics BIOC
Medium
✕
Suspicious Network Connection Originating from AWS SSM Agent
A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011) Exfiltration (TA0010)
ATT&CK techniques: Application Layer Protocol (T1071) Exfiltration Over C2 Channel (T1041)
Detector tags: SSM Remote Management Analytics
Attacker's goals:
Abuse the Amazon SSM agent to establish a covert command and control channel or exfiltrate data outside the cloud environment.
Investigative actions:
Verify the process spawned by SSM agent and validate its legitimacy. Inspect the destination IP and ASN in threat intelligence feeds. Review recent SSM document executions on the affected host.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day