LoFP LoFP / hybrid activation is a legitimate operation when onboarding on-premises or non-ec2 hosts as managed nodes for the first time, and re-registration after an agent reinstall. de-registration (\"-register -clear\") does not match this rule. add exceptions for known provisioning automation or onboarding hosts if this fires in expected environments.

Techniques

Sample rules

AWS SSM Agent Registered via Hybrid Activation

Description

Identifies the Amazon SSM Agent invoked with “-register” and a hybrid activation argument on a Linux host. Hybrid activation is how non-EC2 hosts are onboarded as managed nodes, but adversaries with local access can repurpose the pre-installed, root-privileged SSM Agent as a covert remote access trojan by registering it to an attacker-controlled AWS account, gaining a persistent command channel that blends in with legitimate management traffic. On an EC2 instance that already runs the agent under an instance profile, a hybrid registration is highly unusual. The query cannot tell which account received the registration; the investigation guide explains how to confirm it.

Detection logic

event.category : process and host.os.type : linux and event.type : start and
event.action : (ProcessRollup2 or exec or exec_event or start) and
(
  process.name : (amazon-ssm-agent or ssm-agent-worker or ssm-setup-cli) or
  process.executable : (/snap/amazon-ssm-agent/*/amazon-ssm-agent or /usr/bin/amazon-ssm-agent or /usr/bin/ssm-setup-cli)
) and
process.args : (
  (-register or --register) and
  (
    -activation-code or -activation-code=* or --activation-code or --activation-code=* or
    -activation-id or -activation-id=* or --activation-id or --activation-id=* or
    -code or -code=* or --code or --code=* or
    -id or -id=* or --id or --id=*
  )
)