AWS CloudShell
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS CloudShell rules that match the service but not a specific eventName. | N | N |
| Create | Creates a new AWS CloudShell environment, provisioning a pre-authenticated browser-based shell session with AWS CLI access. | N | Y |
any: AWS CloudShell (catch-all)
#Description
Catch-all entry for AWS CloudShell rules that match the service but not a specific eventName.
CreateEnvironment
#Description
Creates a new AWS CloudShell environment, provisioning a pre-authenticated browser-based shell session with AWS CLI access.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1059, T1059.009, T1078, T1078.004