
Summary
Technical summary: This rule detects a GenAI coding agent spawning a cloud CLI command that destroys infrastructure or identities (e.g., terminating EC2 instances, deleting S3 buckets, or removing IAM users) by matching a process-start event where the parent process is a GenAI agent variant (e.g., qterm, kiro, claude, codex, copilot, etc.) running in a shell (bash, zsh, sh, cmd.exe, powershell, pwsh) and the command line invokes destructive AWS CLI actions or equivalent cloud-destructive operations (ec2 terminate-instances, s3 rb --recursive, iam delete-user, rds delete-db-instance, terraform destroy, kubectl delete, etc.). The rule explicitly excludes benign invocations with --dry-run or help arguments. It accounts for autonomous or interactive agent modes and checks for related prompts or injected content in the agent’s context. MITRE ATT&CK mappings include Data Destruction (T1485) and Account Access Removal (T1531) under Impact, and Impair Defenses (T1562.008) under Defense Evasion. Data sources, correlation, and detection rely on endpoint process start events from the logs-endpoint.events.process* index and a KQL-based query that recognizes the described parent-child patterns and destructive payloads. References to real-world advisories (AWS-2025-015) and related disclosures are provided. The note contains triage guidance, investigation steps, and remediation suggestions such as validating intent, reviewing full CLI arguments, correlating with change-management records, performing CloudTrail checks, and rotating credentials. The rule is designed for Elastic Defend with Fleet integration on endpoints and cloud workloads.
Categories
- Endpoint
- Cloud
- AWS
- Linux
- macOS
- Windows
- Kubernetes
Data Sources
- Process
ATT&CK Techniques
- T0051
- T1485
- T1531
- T1562
- T1562.008
Created: 2026-09-14