AWS SSM Agent Registered via Hybrid Activation
Identifies the Amazon SSM Agent invoked with "-register" and a hybrid activation argument on a Linux host. Hybrid activation is how non-EC2 hosts are onboarded as managed nodes, but adversaries with local access can…
Description
Identifies the Amazon SSM Agent invoked with "-register" and a hybrid activation argument on a Linux host. Hybrid activation is how non-EC2 hosts are onboarded as managed nodes, but adversaries with local access can repurpose the pre-installed, root-privileged SSM Agent as a covert remote access trojan by registering it to an attacker-controlled AWS account, gaining a persistent command channel that blends in with legitimate management traffic. On an EC2 instance that already runs the agent under an instance profile, a hybrid registration is highly unusual. The query cannot tell which account received the registration; the investigation guide explains how to confirm it.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersLinuxmacOSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- event_index
Known benign triggers
- Hybrid activation is a legitimate operation when onboarding on-premises or non-EC2 hosts as managed nodes for the first time, and re-registration after an agent reinstall. De-registration ("-register -clear") does not match this rule. Add exceptions for known provisioning automation or onboarding hosts if this fires in expected environments.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| thehackernews.com/2023/08/researchers-uncover-aws-ssm-agent.html | Only this detection cites it |
| www.mitiga.io/blog/abusing-the-amazon-web-services-ssm-agent-as-a-remote-access-trojan | 3 |
| www.paloaltonetworks.com/blog/security-operations/aws-systems-manager-attack-vectors/ | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- 5f366163-8de9-46ad-91d2-541deaf56864
- Tagged by the source as
- Data Source: CrowdstrikeData Source: Elastic DefendData Source: SentinelOneDomain: CloudDomain: EndpointOS: LinuxPlatform: AWSPlatform: LinuxResources: Investigation GuideRule Type: Custom Query (KQL)Service: AWS SSMTactic: Command and ControlTactic: Persistence
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Sep 30, 2026
- Version
- 1