Suspicious Security Group Ingress Rule Opened to the Internet via CloudTrail

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-09-14
Updated
2026-09-14

ATT&CK techniques

Initial Access → Persistence
  1. Recon

  2. Resource Dev

  3. Execution

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects AuthorizeSecurityGroupIngress events that add an ingress rule allowing the 0.0.0.0/0 or ::/0 CIDR range. Adversaries widen security groups to the entire internet to expose management and database service ports such as SSH, RDP, MySQL, and Redis for remote access or lateral movement. Opening a security group to any source weakens network boundaries and is a common precursor to exploitation.

Related detections9 linkedT1133 — drag to rearrange
SplashTop Network
Suspicious SoftEther VPN Hamcore Config Written to ProgramData (via file_event)
SplashTop Process
AnyDesk Network
OpenCanary RDP New Connection Attempt on Application Logtype 14001
ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
FortiGate: Addition of VPN SSL Web Portal via Event Logs
FortiGate SSL VPN Settings Edited
Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Suspicious Security Group Ingress Rule Opened to the Internet via CloudTrail
Pivot detection · T1133 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.