LoFP LoFP / build systems and ci runners frequently compile or download binaries into temporary directories and then make aws api calls as part of integration tests. exclude known runner paths and restrict to interactive or production hosts if alert volume is high.

Techniques

Sample rules

AWS Control Plane Access by Suspicious Process

Description

Identifies a process running from a temporary or user-writable directory, or a script interpreter executing a payload from such a directory, followed by a network connection to an AWS identity, secrets, or management control plane endpoint. This detects credential abuse performed through an AWS SDK such as boto3, aws-sdk-js, or the Go SDK rather than through the aws command line binary. Rules that key on the CLI process name are bypassed entirely by SDK based tooling, which is what most post exploitation malware and supply chain stealers actually use, so this rule is intended as the name independent complement to them.

Detection logic

event.category : network and host.os.type : (linux or macos or windows) and
dns.question.name : (
  iam.amazonaws.com or sts.amazonaws.com or bedrock*.amazonaws.com or kms.*.amazonaws.com or organizations.*.amazonaws.com or
  portal.sso.*.amazonaws.com or secretsmanager.*.amazonaws.com or ssm.*.amazonaws.com or sso.*.amazonaws.com or
  sts.*.amazonaws.com
) and
process.executable : (
  (
    *\\ProgramData\\* or *\\Users\\*\\AppData\\Local\\Temp\\* or *\\Users\\Public\\* or *\\Windows\\Temp\\* or
    /Users/*/Public/* or /Users/Shared/* or /dev/shm/* or /private/tmp/* or /run/* or /tmp/* or /var/run/* or
    /var/tmp/* or /var/www/*
  ) and
  not (/opt/actions-runner/* or /tmp/cargo-install* or /tmp/go-build* or /tmp/pytest-*)
)