Potential Amazon SSM Agent Hijacking

Rule Info

Name
Potential Amazon SSM Agent Hijacking
Author
Muhammad Faisal
Description
Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
Date
2023-08-02 00:00:00
Modified
None
Id
d20ee2f4-822c-4827-9e15-41500b1fff10
Tags
attack.command-and-control attack.persistence attack.t1219.002
Type
Community Rule

Rule History

Author
Title
Date
Commit
phantinuss
Merge PR #5477 from @phantinuss - chore: update MITRE tag t1219 to t1219.002
2025-06-13
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
github-actions[bot]
Merge PR #4867 from @nasbench - Promote older rules status from `experimental` to `test`
2024-06-03
Wagga
Merge PR #4524 from @wagga40 - Fix Typos In Metadata Fields
2023-10-28
z00t
feat: add new rule related to "Amazon SSM Agent" potential abuse (#4369)
2023-08-03