AWS CloudTrail: TruffleHog User-Agent Execution Detected

Flags AWS CloudTrail events with user agent "TruffleHog" to surface potential secret-scanning or credential-harvesting activity.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-10-21
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags AWS CloudTrail events where the user agent is exactly "TruffleHog," indicating the tool was executed in the AWS environment. Attackers may use secret-scanning utilities to locate exposed credentials or other sensitive information before attempting access. The detection relies on CloudTrail telemetry that includes the userAgent field, matched to the specific string value.

Related detections9 linkedT1003 — drag to rearrange
Suspicious Veeam Backup Credential Harvesting via PowerShell (via ps_script)
Suspicious ALPHA SPIDER Veeam Backup Credential Extraction (via process_creation)
Malicious Wdigest Authentication Enabled - Reg via Command (via process_creation)
Malicious Diskshadow Command Abuse to Expose VSS Backup (via process_creation)
Malicious IIS Application Pool Credential Dumping (via process_creation)
Malicious User Files Dump via Network Share - DonPapi, Lazagne (via security)
Malicious Wdigest Authentication Enabled - Registry (via registry_set)
Malicious User Application Credentials Dump via Network Share - DonPapi, Lazagne (via security)
Malicious Veeam Credential Theft via PowerShell (via ps_script)
AWS CloudTrail: TruffleHog User-Agent Execution Detected
Pivot detection · T1003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.