New Amazon EC2 Instance type
Goal
Detect when an attacker spawns an instance for malicious purposes.
Strategy
This rule lets you monitor this CloudTrail API call to detect when a new instance type (@responseElements.instancesSet.items.instanceType
) is spawned:
It does this by inspecting the AWS Instance types each AWS account are seen over a 7-day window. Newly detected instance types after this 7-day window till generate security signals.
Triage and response
- Determine whether the instance type
{{@responseElements.instancesSet.items.instanceType}}
is expected to be used in your AWS account by checking the Datadog Infrastructure List. - If not, determine who spawned this instance and ask the user whether their activity was legitimate or whether their credentials were compromised and this instance is being used by an attacker.
Changelog
7 April 2022 - Updated rule query.