AWS Control Plane Access by Suspicious Process
Identifies a process running from a temporary or user-writable directory, or a script interpreter executing a payload from such a directory, followed by a network connection to an AWS identity, secrets, or management…
Description
Identifies a process running from a temporary or user-writable directory, or a script interpreter executing a payload from such a directory, followed by a network connection to an AWS identity, secrets, or management control plane endpoint. This detects credential abuse performed through an AWS SDK such as boto3, aws-sdk-js, or the Go SDK rather than through the aws command line binary. Rules that key on the CLI process name are bypassed entirely by SDK based tooling, which is what most post exploitation malware and supply chain stealers actually use, so this rule is intended as the name independent complement to them.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- IaaSIdentity ProviderOffice SuiteSaaS
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- event_index
Known benign triggers
- Build systems and CI runners frequently compile or download binaries into temporary directories and then make AWS API calls as part of integration tests. Exclude known runner paths and restrict to interactive or production hosts if alert volume is high.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| thehackernews.com/2024/11/malicious-pypi-package-fabrice-found.html | Only this detection cites it |
| unit42.paloaltonetworks.com/teamtnt-operations-cloud-environments/ | Only this detection cites it |
| www.sentinelone.com/labs/cloudy-with-a-chance-of-credentials-aws-targeting-cred-stealer-expands-to-azure-gcp/ | Only this detection cites it |
| www.sysdig.com/blog/ai-assisted-cloud-intrusion-achieves-admin-access-in-8-minutes | Only this detection cites it |
| www.sysdig.com/blog/cloud-breach-terraform-data-theft | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- ffba7c69-13b3-4b6d-a747-2947e73c967c
- Tagged by the source as
- Data Source: Elastic DefendDomain: CloudDomain: EndpointOS: LinuxOS: macOSOS: WindowsPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsResources: Investigation GuideRule Type: New TermsService: AWS BedrockService: AWS IAMService: AWS KMSService: AWS Secrets ManagerService: AWS SSMService: AWS STSTactic: Discovery
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Sep 30, 2026
- Version
- 1