AWS Java_Ghost security group creation attempt
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Goal
Detect when an attempt to create an AWS security group called “Java_Ghost” is observed.
Strategy
Monitor CloudTrail and detect when an attempt to create an AWS security group called “Java_Ghost” has been observed. Datadog’s security research team has assessed with high confidence that an occurrence of this event likely means that identity {{@userIdentity.arn}}
has been compromised. An attacker may try to create a security group to maintain access to any EC2 instances created.
Triage and response
- Determine other actions taken by the identity
{{@userIdentity.arn}}
by looking at past activity and the types of API calls occurring. - Begin your company’s incident response process and an investigation.