AWS EC2 User Data Retrieval for EC2 Instance
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Identifies discovery requestDescribeInstanceAttributewith the attribute userData and instanceId in AWS CloudTrail logs. This may indicate an attempt to retrieve user data from an EC2 instance. Adversaries may use this information to gather sensitive data from the instance such as hardcoded credentials or to identify potential vulnerabilities. This is aNew Termsrule that identifies whenaws.cloudtrail.user_identity.arnrequests the user data for a specificaws.cloudtrail.flattened.request_parameters.instanceIdfrom an EC2 instance in the last 14 days.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "DETECTION_ACTION_AWS_EC2_USER_DATA_RETRIEVED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS
Detection
Execution Mode
realtime
Log Sources
AWS


