Analytics Story: Unusual AWS EC2 Modifications

REMOVED ANALYTIC STORY

This analytic story has been removed from the Splunk Threat Research content library and is no longer maintained or supported.

Reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity

Removed in version: 5.2.0

Replacement: Suspicious Cloud Instance Activities

If you have any questions or concerns, please reach out to us at research@splunk.com.

Description

Identify unusual changes to your AWS EC2 instances that may indicate malicious activity. Modifications to your EC2 instances by previously unseen users is an example of an activity that may warrant further investigation.

Why it matters

A common attack technique is to infiltrate a cloud instance and make modifications. The adversary can then secure access to your infrastructure or hide their activities. So it's important to stay alert to changes that may indicate that your environment has been compromised. Searches within this Analytic Story can help you detect the presence of a threat by monitoring for EC2 instances that have been created or changed--either by users that have never previously performed these activities or by known users who modify or create instances in a way that have not been done before. This story also provides investigative searches that help you go deeper once you detect suspicious behavior.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼

References


Version: 1