Title:
Potential Malicious Usage of CloudTrail System Manager
Status:
test
Description:Detect when System Manager successfully executes commands against an instance.
References:
-https://github.com/elastic/detection-rules/blob/v8.6.0/rules/integrations/aws/initial_access_via_system_manager.toml
Author: jamesc-grafana
Date: 2024-07-11
modified:2025-12-08
Tags:
- -'attack.privilege-escalation'
- -'attack.initial-access'
- -'attack.t1566'
- -'attack.t1566.002'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection_event:
eventName:
'SendCommand'
eventSource:
'ssm.amazonaws.com'
selection_status_success:
errorCode:
'Success'
selection_status_null:
errorCode:
'None'
condition:
selection_event and 1 of selection_status_*
Falsepositives:
-There are legitimate uses of SSM to send commands to EC2 instances
-Legitimate users may have to use SSM to perform actions against machines in the Cloud to update or maintain them
Level:
high