
Summary
Detection rule that flags execution of known cloud offensive, enumeration, and attack-simulation frameworks on endpoints. It monitors process start events where the executable name matches tools such as Pacu, CloudFox, ScoutSuite, PMapper, Stratus Red Team, WeirdAAL, and others listed, or where a launcher (Python, Go, Node, uv, pipx, etc.) runs a command line referencing these tools. It also accounts for common launcher patterns and excludes certain build/install activities (e.g., pip install, go build) to reduce false positives. The rule is designed to catch adversaries after obtaining cloud credentials to map permissions, discover escalation paths, and pivot to cloud consoles. It maps to MITRE ATT&CK techniques for Cloud Infrastructure Discovery (T1580) and Cloud Groups (T1069.003) under Discovery, and Command and Scripting Interpreter with Python (T1059.006) under Execution. It includes alert suppression logic to de-duplicate signals by host, process, and command line within a short window. A comprehensive triage guide is provided for investigators to verify tooling usage, correlate with cloud audit logs (e.g., CloudTrail), and determine if there is authorized red-team or cloud security assessment activity. The rule emphasizes correlation with known assessment windows and operator identities, and recommends containment and credential rotation if unauthorized.
Categories
- Endpoint
- Cloud
- AWS
Data Sources
- Process
ATT&CK Techniques
- T1580
- T1069
- T1069.003
- T1059
- T1059.006
Created: 2026-09-14