Techniques
Sample rules
AWS Lambda Function Invoked Cross-Account
- source: elastic
- technicques:
- T1648
Description
Identifies an AWS Lambda function invoked by a principal whose AWS account differs from the account that owns the function (a cross-account invocation). The caller’s account is parsed from the invoking principal’s ARN and compared to the function account. Adversaries who have been granted invoke permission on a function from an external account, or who operate from a separate attacker-controlled account, can use cross-account invocation to execute functions or retrieve the data they return. This is the data-plane counterpart to detecting the cross-account grant itself, and relies on AWS Lambda data event logging, which is not enabled by default.
Detection logic
from logs-aws.cloudtrail-*
| where
event.provider == "lambda.amazonaws.com"
and event.action like "Invoke*"
and event.outcome == "success"
and aws.cloudtrail.user_identity.arn IS NOT NULL
and aws.cloudtrail.user_identity.invoked_by IS NULL
and aws.cloudtrail.request_parameters IS NOT NULL
| grok aws.cloudtrail.user_identity.arn """:(?<Esql.caller_account>[0-9]{12}):"""
| grok aws.cloudtrail.request_parameters """functionName=arn:aws:lambda:[a-z0-9-]*:(?<Esql.function_account>[0-9]{12}):"""
| where Esql.caller_account IS NOT NULL and Esql.function_account IS NOT NULL and Esql.caller_account != Esql.function_account
| stats
Esql.invocation_count = count(*),
Esql.source_ips = values(source.ip),
Esql.function_arns = values(aws.cloudtrail.resources.arn)
by
aws.cloudtrail.user_identity.arn,
Esql.caller_account,
Esql.function_account
| keep
aws.cloudtrail.user_identity.arn,
Esql.caller_account,
Esql.function_account,
Esql.function_arns,
Esql.invocation_count,
Esql.source_ips