
Unusual Process Resolving AWS ECS Agent Communication Service Endpoint
Elastic Detection Rules
View SourceSummary
This rule detects a Linux host process other than the Amazon ECS agent performing a DNS lookup for ECS Agent Communication Service (ACS) or Telemetry Service (TACS) hostnames. The ECScape technique exploits the ACS protocol to steal instance-role credentials and impersonate the ECS agent to receive task-role credentials for other tasks on the same host. No container escape is required, and credential theft can cross task boundaries, making non-agent processes contacting ACS/TACS suspicious. The rule flags DNS queries to ecs-a-*.amazonaws.com or ecs-t-*.amazonaws.com initiated by non-agent processes and excludes known legitimate ECS agent binaries. It relies on Elastic Defend data (host/process and network events) to correlate process start information with DNS lookups. The intent is to surface attempts to abuse ECS control channels that should only be used by the ECS agent, enabling rapid investigation of potential credential theft and cross-container abuse on Linux endpoints.
Categories
- Endpoint
- Linux
Data Sources
- Process
- Network Traffic
ATT&CK Techniques
- T1526
- T1580
Created: 2026-09-14