Potential Malicious Usage of CloudTrail System Manager

 Original Source: [Sigma source]
Title: Potential Malicious Usage of CloudTrail System Manager
Status: test
Description:Detect when System Manager successfully executes commands against an instance.
References:
  -https://github.com/elastic/detection-rules/blob/v8.6.0/rules/integrations/aws/initial_access_via_system_manager.toml
Author: jamesc-grafana
Date: 2024-07-11
modified:2025-12-08
Tags:
  • -'attack.privilege-escalation'
  • -'attack.initial-access'
  • -'attack.t1566'
  • -'attack.t1566.002'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection_event:
    eventName: 'SendCommand'
    eventSource: 'ssm.amazonaws.com'
  selection_status_success:
    errorCode: 'Success'
  selection_status_null:
    errorCode: 'None'
  condition:selection_event and 1 of selection_status_*
Falsepositives:
  -There are legitimate uses of SSM to send commands to EC2 instances
  -Legitimate users may have to use SSM to perform actions against machines in the Cloud to update or maintain them
Level: high