
Summary
Identifies Linux hosts where the Amazon SSM Agent is started with a hybrid activation registration (-register) and an activation code/ID argument. Hybrid activation is the onboarding path for non-EC2 hosts, but attackers with local access can repurpose a pre-installed, root-privileged SSM Agent to register to an attacker-controlled AWS account, creating a persistent command channel that blends with legitimate management traffic. On EC2 instances that already run the agent under an instance profile, a hybrid registration is anomalous. The rule cannot determine which account received the registration; the accompanying investigation guide explains how to confirm it. Detection relies on process-start events for the agent (amazon-ssm-agent, ssm-agent-worker, ssm-setup-cli) and the presence of -register (or --register) combined with activation-code, activation-id, code, or id arguments in the process arguments. It aggregates data across Elastic Defend, CrowdStrike, and SentinelOne sources using process-start signals. This behavior maps to MITRE ATT&CK techniques T1219 (Remote Access Tools) and T1133 (External Remote Services), indicating possible command-and-control or persistence activity if the registration is to a malicious AWS account.
Categories
- Endpoint
- Linux
- AWS
- Cloud
Data Sources
- Process
ATT&CK Techniques
- T1219
- T1133
Created: 2026-09-14