Back to results

Unusual Process Resolving AWS ECS Agent Communication Service Endpoint

Identifies a process other than the Amazon ECS agent performing a DNS lookup for an ECS Agent Communication Service (ACS) or Telemetry Service (TACS) hostname on a Linux host. The ECScape technique abuses the…

Description

Identifies a process other than the Amazon ECS agent performing a DNS lookup for an ECS Agent Communication Service (ACS) or Telemetry Service (TACS) hostname on a Linux host. The ECScape technique abuses the undocumented ACS protocol: a compromised container that can reach the instance metadata service steals the EC2 instance role credentials, then impersonates the ECS agent over ACS to receive the task role credentials of every other task scheduled on the same host. No container escape is required, and the credential theft crosses task boundaries that operators assume are isolated. Only the ECS agent should be speaking this protocol.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
IaaSIdentity ProviderOffice SuiteSaaS

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Known benign triggers

  • Custom ECS agent implementations or ECS-agent-compatible schedulers may legitimately contact ACS. Add their executable paths to the exclusion list. Allowlist known sidecar executable paths if alert volume from those containers is high.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice