Suspicious EC2 Serial Console SSH Public Key Push (via cloudtrail)

PremiumReviewedSigma · High · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-07-23
Updated
2026-08-28

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects the SendSerialConsoleSSHPublicKey call used to push an SSH key to an instance serial console, an uncommon access path adversaries leverage to reach hosts that block normal network SSH. Legitimate serial console use is rare, so this event strongly suggests an attacker seeking out of band interactive access to a cloud instance.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.