heroui logo

AWS Control Plane Access by Suspicious Process

Elastic Detection Rules

View Source
Summary
Detects credential theft or abuse via AWS SDKs by watching for a process executing from a temporary or user-writable directory (e.g., /tmp, user Temp, Public folders) or a script interpreter running payloads from such paths, followed by a DNS query to AWS control-plane endpoints (e.g., iam.amazonaws.com, sts.amazonaws.com, secretsmanager.*, kms.*). This targets SDK-based access to AWS services (boto3, aws-sdk-js, Go SDK) rather than CLI utilities, addressing post-exploitation tooling that bypasses CLI-name based detections. The rule maps to MITRE techniques Cloud Service Discovery (T1526) and Cloud Infrastructure Discovery (T1580) under the Discovery tactic, and is intended as a name-independent complement to CLI-based detections. It relies on data from Elastic Defend on endpoints and network events to correlate suspicious process conduct with subsequent AWS DNS lookups. A false positive is expected for CI/build systems that run tests from temporary directories and perform real AWS calls; exclusions for known runner paths or non-interactive production hosts may be necessary. The rule is designed to support incident response by triaging for credential exposure, rotating credentials, reviewing AWS CloudTrail for actions tied to the host, and scanning for additional payloads.
Categories
  • Endpoint
  • Cloud
  • AWS
Data Sources
  • Process
  • Network Traffic
ATT&CK Techniques
  • T1526
  • T1580
Created: 2026-09-14