AWS CloudTrail SSM SendCommand Successful Execution for Instance

Identifies successful AWS SSM SendCommand executions recorded in CloudTrail.

FreeReviewedSigma · High · v5
Product
aws
Service
cloudtrail
Author
jamesc-grafana (SigmaHQ), DRL 1.1
Published
2024-07-11
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags CloudTrail events where AWS Systems Manager (SSM) successfully runs a SendCommand to an instance. Successful command execution is significant because attackers can use SSM to execute actions on managed hosts without direct interactive access. The detection relies on CloudTrail telemetry for eventName "SendCommand", eventSource "ssm.amazonaws.com", and an errorCode of "Success" (including the matching null/errorCode-null success condition).

Related detections9 linkedT1566.002 — drag to rearrange
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
Suspicious NFe-Themed Brazilian Lure Executable Execution
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
Malicious Credential Harvesting Request via All-in-1 PHP Endpoint (via proxy)
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Suspicious 0ktapus Phishing Kit Credential Post Path Access
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Pivot detection · T1566.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.