Potential Malicious Usage of CloudTrail System Manager

Rule Info

Name
Potential Malicious Usage of CloudTrail System Manager
Author
jamesc-grafana
Description
Detect when System Manager successfully executes commands against an instance.
Date
2024-07-11 00:00:00
Modified
None
Id
38e7f511-3f74-41d4-836e-f57dfa18eead
Tags
attack.privilege-escalation attack.t1566 attack.t1566.002 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
James C
Merge PR #4900 from @jamesc-grafana - Add new AWS cloudtrail rules
2024-07-11