AWS EC2 Deprecated AMI Discovery

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Identifies when a user has queried for deprecated Amazon Machine Images (AMIs) in AWS. This may indicate an adversary whom is looking for outdated AMIs that may be vulnerable to exploitation. While deprecated AMIs are not inherently malicious or indicate breach, they may be more susceptible to vulnerabilities and should be investigated for potential security risks.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_AWS_EC2_AMI_DISCOVERED" AND (REQUESTPARAMETERS contains "includedeprecated:true") select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS

Detection

Execution Mode

realtime

Log Sources

AWS