
Rule Info
Name
Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
Author
jamesc-grafana
Description
Detects when an instance identity has taken an action that isn't inside SSM.
This can indicate that a compromised EC2 instance is being used as a pivot point.
Date
2024-07-11 00:00:00
Modified
None
Id
352a918a-34d8-4882-8470-44830c507aa3
Tags
attack.privilege-escalation attack.defense-evasion attack.t1078 attack.t1078.002
Type
Community Rule
Link to Public Repo