mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
e228bd7951
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>
Removed changes from:
- rules/cross-platform/command_and_control_kubectl_networking_modification.toml
- rules/cross-platform/defense_evasion_potential_kubectl_impersonation.toml
- rules/cross-platform/defense_evasion_potential_kubectl_masquerading.toml
- rules/cross-platform/discovery_kubectl_permission_discovery.toml
- rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml
- rules/cross-platform/discovery_web_server_remote_file_inclusion_activity.toml
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml
- rules/cross-platform/initial_access_exfiltration_new_usb_device_mounted.toml
- rules/integrations/aws/initial_access_iam_session_token_used_from_multiple_addresses.toml
- rules/integrations/aws/persistence_aws_attempt_to_register_virtual_mfa_device.toml
- rules/integrations/aws/persistence_iam_api_calls_via_user_session_token.toml
- rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_attached_to_role.toml
- rules/integrations/aws/privilege_escalation_iam_update_assume_role_policy.toml
- rules/integrations/azure/ml_azure_rare_method_by_city.toml
- rules/integrations/azure/ml_azure_rare_method_by_country.toml
- rules/integrations/azure/ml_azure_rare_method_by_user.toml
- rules/integrations/azure/persistence_entra_id_service_principal_federated_issuer_modified.toml
- rules/integrations/cloud_defend/command_and_control_curl_socks_proxy_detected_inside_container.toml
- rules/integrations/cloud_defend/command_and_control_interactive_file_download_from_internet.toml
- rules/integrations/cloud_defend/command_and_control_tunneling_and_port_forwarding.toml
- rules/integrations/cloud_defend/credential_access_cloud_creds_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_collection_sensitive_files_compression_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_sensitive_keys_or_passwords_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_service_account_token_or_cert_read.toml
- rules/integrations/cloud_defend/defense_evasion_decoded_payload_piped_to_interpreter.toml
- rules/integrations/cloud_defend/defense_evasion_file_creation_execution_deletion_cradle.toml
- rules/integrations/cloud_defend/defense_evasion_interactive_process_execution_from_suspicious_directory.toml
- rules/integrations/cloud_defend/defense_evasion_ld_preload_shared_object_modified_inside_a_container.toml
- rules/integrations/cloud_defend/defense_evasion_potential_evasion_via_encoded_payload.toml
- rules/integrations/cloud_defend/discovery_dns_enumeration.toml
- rules/integrations/cloud_defend/discovery_environment_enumeration.toml
- rules/integrations/cloud_defend/discovery_kubelet_certificate_file_access.toml
- rules/integrations/cloud_defend/discovery_kubelet_pod_discovery_via_builtin_utilities.toml
- rules/integrations/cloud_defend/discovery_privilege_boundary_enumeration_from_interactive_process.toml
- rules/integrations/cloud_defend/discovery_service_account_namespace_read.toml
- rules/integrations/cloud_defend/discovery_suspicious_network_tool_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_container_management_binary_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_direct_interactive_kubernetes_api_request.toml
- rules/integrations/cloud_defend/execution_interactive_file_creation_in_system_binary_locations.toml
- rules/integrations/cloud_defend/execution_kubeletctl_execution.toml
- rules/integrations/cloud_defend/execution_netcat_listener_established_inside_a_container.toml
- rules/integrations/cloud_defend/execution_payload_downloaded_and_piped_to_shell.toml
- rules/integrations/cloud_defend/execution_potential_direct_kubelet_access_via_process_args.toml
- rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml
- rules/integrations/cloud_defend/execution_suspicious_interactive_interpreter_command_execution.toml
- rules/integrations/cloud_defend/execution_tool_installation.toml
- rules/integrations/cloud_defend/persistence_modification_of_persistence_relevant_files.toml
- rules/integrations/cloud_defend/persistence_ssh_authorized_keys_modification_inside_a_container.toml
- rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml
- rules/integrations/cloud_defend/persistence_suspicious_webserver_child_process_execution.toml
- rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml
- rules/integrations/cloud_defend/privilege_escalation_potential_container_escape_via_modified_release_agent_file.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_city.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_country.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_user.toml
- rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml
- rules/linux/discovery_docker_socket_discovery.toml
- rules/linux/discovery_kubeconfig_file_discovery.toml
- rules/linux/execution_kubectl_apply_pod_from_url.toml
- rules/linux/lateral_movement_kubeconfig_file_activity.toml
- rules/linux/persistence_kubernetes_sensitive_file_activity.toml
- rules/windows/execution_windows_script_from_internet.toml
- rules_building_block/discovery_kubectl_workload_and_cluster_discovery.toml
(selectively cherry picked from commit 8993d1450b)
157 lines
6.3 KiB
TOML
157 lines
6.3 KiB
TOML
[metadata]
|
|
creation_date = "2026/03/12"
|
|
integration = ["aws"]
|
|
maturity = "production"
|
|
updated_date = "2026/03/24"
|
|
|
|
[rule]
|
|
author = ["Elastic"]
|
|
description = """
|
|
Identifies the creation of a new AWS CloudShell environment. CloudShell is a browser-based shell that provides
|
|
command-line access to AWS resources directly from the AWS Management Console. The CreateEnvironment API is called when
|
|
a user launches CloudShell for the first time or when accessing CloudShell in a new AWS region. Adversaries with console
|
|
access may use CloudShell to execute commands, install tools, or interact with AWS services without needing local CLI
|
|
credentials. Monitoring environment creation helps detect unauthorized CloudShell usage from compromised console
|
|
sessions.
|
|
"""
|
|
false_positives = [
|
|
"""
|
|
Legitimate use of CloudShell by administrators for routine AWS management tasks. Verify whether the user has a
|
|
legitimate need for CloudShell access and correlate with recent console login activity. Environment creation also
|
|
occurs when users access CloudShell in a new AWS region.
|
|
""",
|
|
]
|
|
from = "now-6m"
|
|
index = ["filebeat-*", "logs-aws.cloudtrail-*"]
|
|
language = "kuery"
|
|
license = "Elastic License v2"
|
|
name = "AWS CloudShell Environment Created"
|
|
note = """## Triage and analysis
|
|
|
|
### Investigating AWS CloudShell Environment Created
|
|
|
|
AWS CloudShell is a browser-based shell environment that provides instant command-line access to AWS resources without requiring local CLI installation or credential configuration. While this is convenient for legitimate administrators, it also provides adversaries with a powerful tool if they gain access to a compromised AWS console session.
|
|
|
|
This rule detects when a CloudShell environment is created via the `CreateEnvironment` API. This event occurs when a user launches CloudShell for the first time or when accessing CloudShell in a new AWS region (each region maintains a separate environment).
|
|
|
|
### Possible investigation steps
|
|
|
|
- **Identify the actor**
|
|
- Review `aws.cloudtrail.user_identity.arn` or `user.name` to determine which IAM principal created the CloudShell environment.
|
|
- Check `aws.cloudtrail.user_identity.type` to identify whether this is an IAM user or an assumed role session.
|
|
- Verify if this user typically performs command-line or administrative operations.
|
|
|
|
- **Analyze the source context**
|
|
- Review `source.ip` and `source.geo` fields to verify the request origin matches expected administrator locations.
|
|
- Check `user_agent.original` to confirm the request came from a browser session.
|
|
- Look for the preceding `ConsoleLogin` event to understand how the session was established.
|
|
|
|
- **Correlate with surrounding activity**
|
|
- Look for any IAM operations (CreateAccessKey, CreateUser, AttachRolePolicy) that occurred after CloudShell was accessed.
|
|
- Check for data exfiltration patterns or reconnaissance activity from the same session.
|
|
|
|
- **Assess the broader context**
|
|
- Determine if this user has a legitimate need for CloudShell access based on their role.
|
|
- Review recent access patterns for the console session that initiated CloudShell.
|
|
- Check if MFA was used for the console login.
|
|
|
|
### False positive analysis
|
|
|
|
- Administrators routinely using CloudShell for AWS management tasks will trigger this rule. Consider tuning for known admin users if noise is a concern.
|
|
- Users accessing CloudShell in a new AWS region will generate a `CreateEnvironment` event even if they have used CloudShell before in other regions.
|
|
- Training or certification activities may involve CloudShell environment creation.
|
|
|
|
### Response and remediation
|
|
|
|
- If unauthorized, immediately terminate the console session to revoke CloudShell access.
|
|
- Review and revoke any credentials or resources created during the CloudShell session.
|
|
- Consider restricting CloudShell access via SCPs or IAM policies for sensitive accounts or users who do not require it.
|
|
- Implement session duration limits to reduce the window of opportunity for console session abuse.
|
|
- Enable MFA for all console logins to reduce the risk of session compromise.
|
|
|
|
### Additional information
|
|
|
|
- **[AWS IR Playbooks](https://github.com/aws-samples/aws-incident-response-playbooks/)**
|
|
- **[AWS Customer Playbook Framework](https://github.com/aws-samples/aws-customer-playbook-framework/tree/a8c7b313636b406a375952ac00b2d68e89a991f2/docs)**
|
|
"""
|
|
references = [
|
|
"https://aws-samples.github.io/threat-technique-catalog-for-aws/Techniques/T1059.009.html",
|
|
"https://permiso.io/blog/lucr-3-scattered-spider-getting-saas-y-in-the-cloud",
|
|
]
|
|
risk_score = 21
|
|
rule_id = "b625c9ad-16e5-4f16-8d38-3e9631952554"
|
|
severity = "low"
|
|
tags = [
|
|
"Domain: Cloud",
|
|
"Data Source: AWS",
|
|
"Data Source: Amazon Web Services",
|
|
"Data Source: AWS CloudTrail",
|
|
"Data Source: AWS CloudShell",
|
|
"Use Case: Threat Detection",
|
|
"Tactic: Execution",
|
|
"Resources: Investigation Guide",
|
|
]
|
|
timestamp_override = "event.ingested"
|
|
type = "query"
|
|
|
|
query = '''
|
|
event.dataset: "aws.cloudtrail"
|
|
and event.provider: "cloudshell.amazonaws.com"
|
|
and event.action: "CreateEnvironment"
|
|
and event.outcome: "success"
|
|
'''
|
|
|
|
|
|
[[rule.threat]]
|
|
framework = "MITRE ATT&CK"
|
|
|
|
[[rule.threat.technique]]
|
|
id = "T1059"
|
|
name = "Command and Scripting Interpreter"
|
|
reference = "https://attack.mitre.org/techniques/T1059/"
|
|
|
|
[[rule.threat.technique.subtechnique]]
|
|
id = "T1059.009"
|
|
name = "Cloud API"
|
|
reference = "https://attack.mitre.org/techniques/T1059/009/"
|
|
|
|
[rule.threat.tactic]
|
|
id = "TA0002"
|
|
name = "Execution"
|
|
reference = "https://attack.mitre.org/tactics/TA0002/"
|
|
|
|
[[rule.threat]]
|
|
framework = "MITRE ATT&CK"
|
|
|
|
[[rule.threat.technique]]
|
|
id = "T1078"
|
|
name = "Valid Accounts"
|
|
reference = "https://attack.mitre.org/techniques/T1078/"
|
|
|
|
[[rule.threat.technique.subtechnique]]
|
|
id = "T1078.004"
|
|
name = "Cloud Accounts"
|
|
reference = "https://attack.mitre.org/techniques/T1078/004/"
|
|
|
|
[rule.threat.tactic]
|
|
id = "TA0001"
|
|
name = "Initial Access"
|
|
reference = "https://attack.mitre.org/tactics/TA0001/"
|
|
[rule.investigation_fields]
|
|
field_names = [
|
|
"@timestamp",
|
|
"user.name",
|
|
"user_agent.original",
|
|
"source.ip",
|
|
"aws.cloudtrail.user_identity.arn",
|
|
"aws.cloudtrail.user_identity.type",
|
|
"aws.cloudtrail.user_identity.access_key_id",
|
|
"event.action",
|
|
"event.outcome",
|
|
"cloud.account.id",
|
|
"cloud.region",
|
|
"aws.cloudtrail.request_parameters",
|
|
"aws.cloudtrail.response_elements",
|
|
]
|
|
|