Techniques
Sample rules
AWS SSM Agent Registered via Hybrid Activation
- source: elastic
- technicques:
- T1133
- T1219
Description
Identifies the Amazon SSM Agent invoked with “-register” and a hybrid activation argument on a Linux host. Hybrid activation is how non-EC2 hosts are onboarded as managed nodes, but adversaries with local access can repurpose the pre-installed, root-privileged SSM Agent as a covert remote access trojan by registering it to an attacker-controlled AWS account, gaining a persistent command channel that blends in with legitimate management traffic. On an EC2 instance that already runs the agent under an instance profile, a hybrid registration is highly unusual. The query cannot tell which account received the registration; the investigation guide explains how to confirm it.
Detection logic
event.category : process and host.os.type : linux and event.type : start and
event.action : (ProcessRollup2 or exec or exec_event or start) and
(
process.name : (amazon-ssm-agent or ssm-agent-worker or ssm-setup-cli) or
process.executable : (/snap/amazon-ssm-agent/*/amazon-ssm-agent or /usr/bin/amazon-ssm-agent or /usr/bin/ssm-setup-cli)
) and
process.args : (
(-register or --register) and
(
-activation-code or -activation-code=* or --activation-code or --activation-code=* or
-activation-id or -activation-id=* or --activation-id or --activation-id=* or
-code or -code=* or --code or --code=* or
-id or -id=* or --id or --id=*
)
)