Cloud Administration Command T1651

Tactic: Execution

Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 27 rules share fields, values, and exclusions.

Fields filtered most (65 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType12in 6, eq 5, wildcard 1exec, exec_event, executed, microsoft.compute/virtualmachines/extensions/write, sendcommand
data_stream.dataset10eq 10azure.activitylogs, aws.cloudtrail, endpoint.events.process, gcp.audit
event.outcome10eq 10success
parent_process_name5eq 5, in 3bash, customscripthandler.exe, dash, powershell.exe, busybox
process_name5eq 3, in 2, ne 1arp.exe, aws, base64, bash, bitsadmin.exe
CommandLine3contains 1, eq 1, is_not_null 1%/document/orchestration/%/awsrunshellscript/%/_script.sh, -enc, -w hidden, downloadfile
Provider_Name3eq 3ssm.amazonaws.com, cloudformation.amazonaws.com
event.category3eq 3process
event.type3eq 2, in 1start, process_started
host.os.type3eq 3, in 1
process.args3contains 2, eq 1, in 1, starts_with 1--parameters, -decode, -encode, aws-runpowershellscript, aws-runshellscript
process.parent.args3wildcard 2, contains 1/var/lib/waagent/run-command/download/*/script.sh, awsrunpowershellscript, awsrunshellscript
ActionType2eq 2, in 1FileCreated, connectionattempt, connectionfailed
AppId2eq 2FociClientApplications
HomeTenantId2cross_field_compare 2ResourceTenantId

Top indicator values (219 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
10369
data_stream.dataseteq
azure.activitylogs
539
data_stream.dataseteq
aws.cloudtrail
4169
event.categoryeq
process
3142
parent_process_nameeq
powershell.exe
339
parent_process_nameeq
customscripthandler.exe
22
parent_process_namein
bash
365
parent_process_namein
dash
342
parent_process_namein
sh
365
ActionTypeeq
FileCreated
27
AppIdeq
FociClientApplications
22
EventTypeeq
sendcommand
22
EventTypein
exec
2201
EventTypein
exec_event
2149
EventTypein
executed
298
EventTypein
microsoft.compute/virtualmachines/extensions/write
22
EventTypein
microsoft.compute/virtualmachinescalesets/extensions/write
22
EventTypein
process_started
283
HomeTenantIdcross_field_compare
ResourceTenantId
23
IncomingTokenTypeeq
none
22
IncomingTokenTypene
none
22
ParentCommandLineeq
powershell -executionpolicy unrestricted -file script?.ps1
22
Provider_Nameeq
ssm.amazonaws.com
25
SecondAppDisplayNamein
Microsoft Azure CLI
22
SecondAppDisplayNamein
Microsoft Azure PowerShell
22
event.typeeq
start
21078
process.parent.argswildcard
/var/lib/waagent/run-command/download/*/script.sh
22
process_nameeq
powershell.exe
2184
resultTypein
Succeeded
251
resultTypein
Success
251

Exclusions (57 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
AccountDisplayNamecross_field_compare
ITAccounts
1
AccountUPNcross_field_compare
ITAccounts
1
Applicationcontains
cli
1
Applicationcontains
command line
1
Applicationcontains
management shell
1
Applicationcontains
powershell
1
AssignedRoleseq
0
1
CommandLineends_with
/checkExclusionPreference/_script.sh
1
CommandLineends_with
/checkProvisioningEligibility/_script.sh
1
CommandLineends_with
/install/_script.sh
1
CommandLineends_with
/invokeInspectorSsmPluginLinux/_script.sh
1
CommandLineends_with
/uninstall/_script.sh
1
CommandLineends_with
\createUpdateFolder\_script.ps1
1
CommandLineends_with
ssm-user
1
Departmentcontains
ict
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 16 rules

Kusto 9 rules

Panther 2 rules