AWS CloudTrail: ElastiCache Cache Security Group Created
Flags CloudTrail events indicating a new ElastiCache cache security group was created.
- Product
- aws
- Service
- cloudtrail
- Author
- Austin Songer @austinsonger (SigmaHQ), DRL 1.1
- Published
- 2021-07-24
- Updated
- 2026-07-31
ATT&CK techniques
PersistenceRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies AWS CloudTrail events where an ElastiCache cache security group is created via the CreateCacheSecurityGroup API. Attackers or administrators could use this to alter network access boundaries for ElastiCache resources, potentially enabling unwanted connectivity. Detection relies on CloudTrail telemetry with eventSource set to elasticache.amazonaws.com and eventName set to CreateCacheSecurityGroup.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "AWS CloudTrail: ElastiCache Cache Security Group Created"
id: 2050e2bc-d5cc-4f8f-83c8-53f2639dbab2
status: test
description: This rule identifies AWS CloudTrail events where an ElastiCache cache security group is created via the CreateCacheSecurityGroup API. Attackers or administrators could use this to alter network access boundaries for ElastiCache resources, potentially enabling unwanted connectivity. Detection relies on CloudTrail telemetry with eventSource set to elasticache.amazonaws.com and eventName set to CreateCacheSecurityGroup.
references:
- https://github.com/elastic/detection-rules/blob/598f3d7e0a63221c0703ad9a0ea7e22e7bc5961e/rules/integrations/aws/persistence_elasticache_security_group_creation.toml
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_elasticache_security_group_created.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-07-24
modified: 2022-10-09
tags:
- attack.persistence
- attack.t1136
- attack.t1136.003
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: elasticache.amazonaws.com
eventName: CreateCacheSecurityGroup
condition: selection
falsepositives:
- A ElastiCache security group may be created by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security group creations from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 4ae68615-866f-4304-b24b-ba048dfa5ca7
type: derived