Unusual Process Resolving AWS ECS Agent Communication Service Endpoint
Identifies a process other than the Amazon ECS agent performing a DNS lookup for an ECS Agent Communication Service (ACS) or Telemetry Service (TACS) hostname on a Linux host. The ECScape technique abuses the…
Description
Identifies a process other than the Amazon ECS agent performing a DNS lookup for an ECS Agent Communication Service (ACS) or Telemetry Service (TACS) hostname on a Linux host. The ECScape technique abuses the undocumented ACS protocol: a compromised container that can reach the instance metadata service steals the EC2 instance role credentials, then impersonates the ECS agent over ACS to receive the task role credentials of every other task scheduled on the same host. No container escape is required, and the credential theft crosses task boundaries that operators assume are isolated. Only the ECS agent should be speaking this protocol.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- IaaSIdentity ProviderOffice SuiteSaaS
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
Known benign triggers
- Custom ECS agent implementations or ECS-agent-compatible schedulers may legitimately contact ACS. Add their executable paths to the exclusion list. Allowlist known sidecar executable paths if alert volume from those containers is high.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| docs.aws.amazon.com/AmazonECS/latest/developerguide/task-metadata-endpoint-v4.html | Only this detection cites it |
| www.sweet.security/blog/ecscape-understanding-iam-privilege-boundaries-in-amazon-ecs | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- eec07086-37c7-4285-bfa2-a4ce03c7648c
- Tagged by the source as
- Data Source: Elastic DefendDomain: CloudDomain: EndpointOS: LinuxPlatform: AWSPlatform: LinuxResources: Investigation GuideRule Type: ES|QLTactic: Discovery
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Sep 30, 2026
- Version
- 1