Analytics BIOC Medium

Unusual process executed by AWS Systems Manager

An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter (T1059)
Detector tags: SSM Remote Management Analytics
Attacker's goals:

Adversaries may execute malicious code using legitimate cloud administration tools.

Investigative actions:

Verify if this is a legitimate script or command being run by an administrator using AWS Systems Manager.

Test period:
N/A (single event)
Deduplication:
1 Day