Analytics Story: Suspicious AWS EC2 Activities

REMOVED ANALYTIC STORY

This analytic story has been removed from the Splunk Threat Research content library and is no longer maintained or supported.

Reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity

Removed in version: 5.2.0

Replacement: Suspicious Cloud Instance Activities

If you have any questions or concerns, please reach out to us at research@splunk.com.

Description

Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it.

Why it matters

AWS CloudTrail is an AWS service that helps you enable governance, compliance, and risk auditing within your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Console, AWS command-line interface, and AWS SDKs and APIs to ensure that your EC2 instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your AWS EC2 instances and helps you respond and investigate those activities.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼

References


Version: 1