Techniques
Sample rules
AWS CLI Configuration Modified by Unusual Process
- source: elastic
- technicques:
- T1556
Description
Identifies modification of the AWS CLI configuration or alias files by a process that is not a known credential helper, editor, or provisioning tool. The AWS config file supports a credential_process directive that names an arbitrary local executable to source credentials from; an adversary who writes this directive redirects every subsequent AWS CLI and SDK call through a binary of their choosing, harvesting or substituting credentials without touching the credentials file itself. The CLI alias file offers a similar hijack primitive. This write-side abuse leaves no CloudTrail evidence and is substantially quieter than reading the credentials file.
Only the AWS CLI, credential-helper tools that rewrite this file as part of normal operation, and a few system agent paths are excluded. Editors, IDEs, dotfile managers, configuration management, shells, and copy utilities are intentionally kept in scope: this is a building block, and a human or script writing a credential_process directive is the context higher-order rules need.
Detection logic
event.category : "file" and event.action : (creation or modification or overwrite or rename) and
file.path : (
/root/.aws/cli/alias or /root/.aws/config or
/var/root/.aws/cli/alias or /var/root/.aws/config or
/private/var/root/.aws/cli/alias or /private/var/root/.aws/config or
*\\.aws\\cli\\alias or *\\.aws\\config or
/Users/*/.aws/cli/alias or /Users/*/.aws/config or
/home/*/.aws/cli/alias or /home/*/.aws/config
) and
process.executable : (* and not (/opt/Elastic/Agent/* or /opt/aws/* or /usr/lib/systemd/*)) and
not process.name : (
assume or assumego or aws or aws-azure-login or aws-google-auth or aws-mfa or aws-sso or aws-sso-util or
aws-vault or "aws-vault.exe" or aws.exe or aws_completer or aws_signing_helper or "gimme-aws-creds" or granted or
leapp or "okta-aws-cli" or saml2aws or saml2aws.exe
)