AWS Key Pair Import Activity

Rule Info

Name
AWS Key Pair Import Activity
Author
Ivan Saakov
Description
Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.
Date
2024-12-19 00:00:00
Modified
None
Id
92f84194-8d9a-4ee0-8699-c30bfac59780
Tags
attack.initial-access attack.t1078 attack.persistence attack.privilege-escalation
Type
Community Rule

Rule History

Author
Title
Date
Commit
Ivan S
Merge PR #5023 from @saakovv - Add `AWS Key Pair Import Activity`
2024-12-19