Techniques
Sample rules
Unusual Process Resolving AWS ECS Agent Communication Service Endpoint
- source: elastic
- technicques:
- T1526
- T1580
Description
Identifies a process other than the Amazon ECS agent performing a DNS lookup for an ECS Agent Communication Service (ACS) or Telemetry Service (TACS) hostname on a Linux host. The ECScape technique abuses the undocumented ACS protocol: a compromised container that can reach the instance metadata service steals the EC2 instance role credentials, then impersonates the ECS agent over ACS to receive the task role credentials of every other task scheduled on the same host. No container escape is required, and the credential theft crosses task boundaries that operators assume are isolated. Only the ECS agent should be speaking this protocol.
Detection logic
FROM logs-endpoint.events.network-* METADATA _id, _index, _version
| WHERE host.os.type == "linux"
AND event.action IN ("lookup_requested", "lookup_result")
AND process.executable IS NOT NULL
AND (
TO_LOWER(dns.question.name) LIKE "ecs-a-*.amazonaws.com*" OR
TO_LOWER(dns.question.name) LIKE "ecs-t-*.amazonaws.com*"
)
AND NOT process.name IN ("amazon-ecs-agent", "ecs-agent", "amazon-ssm-agent", "aws-vpc-cni")
AND NOT (
process.executable == "/agent" OR
process.executable == "/usr/bin/amazon-ecs-agent" OR
process.executable LIKE "/managed-agents/*" OR
process.executable LIKE "/usr/libexec/amazon-ecs-*" OR
process.executable LIKE "/var/lib/ecs/*" OR
process.executable LIKE "/opt/Elastic/Agent/*"
)
| KEEP _id, _index, _version, @timestamp, data_stream.namespace, host.id, host.name, user.id, user.name,
process.entity_id, process.parent.entity_id, process.pid, process.name, process.executable, dns.question.name