Skip to content

Add AWS EC2 Instance Connect key upload detection - #4312

Open
themaryjo wants to merge 3 commits into
developfrom
aws-ec2-instance-connect-key-upload-detection
Open

themaryjo wants to merge 3 commits into
developfrom
aws-ec2-instance-connect-key-upload-detection

Conversation

@themaryjo

Copy link
Copy Markdown
Contributor

Adds an AWS CloudTrail behavioral detection for 10 or more successful EC2 Instance Connect SendSSHPublicKey calls by a single identity. The detection uses CIM-compatible fields and includes validated attack data and a passing unit test.

Ingest AWS CloudTrail management events into Splunk using the
aws:cloudtrail sourcetype. Ensure that successful EC2 Instance Connect
SendSSHPublicKey events are collected. Schedule the analytic with a short
lookback window appropriate for the environment, such as 10 minutes, and

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

minor update needed to how to implement to make it generic like other aws_cloudtrail detections.

@patel-bhavin patel-bhavin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

text update needed

@nasbench nasbench added this to the v6.8.0 milestone Oct 2, 2026
@nasbench

nasbench commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T17:22:40.025530Z 9e04e6d Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9e04e6de5d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

values(vendor_region) as vendor_region
earliest(_time) as firstTime
latest(_time) as lastTime
by user

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep AWS account context in the aggregation

In a central CloudTrail index that collects multiple AWS accounts, user_name is not globally unique. Because the preceding coalesce prefers that short name and this aggregation groups only by user, calls made by identically named users such as admin in different accounts are combined and can incorrectly cross the 10-event threshold as a “single identity.” Group by vendor_account as well, or use an account-qualified identity as the grouping key.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@patel-bhavin thoughts?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@codex - what about using user_arn in the by clause, would that be better?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not sure why it didnt reason the above comment but I think user_arn should be good

@splunk splunk deleted a comment from chatgpt-codex-connector Bot Oct 2, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9e04e6de5d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

search: |-
`cloudtrail` eventSource="ec2-instance-connect.amazonaws.com" eventName="SendSSHPublicKey" responseElements.success=true
| eval user=coalesce(user_name, 'userIdentity.arn', 'userIdentity.principalId')
| stats count as event_count

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Deduplicate CloudTrail events before applying the threshold

When the same CloudTrail event is ingested more than once—for example, through overlapping trails or duplicate collection paths—stats count treats every copy as a separate SSH-key upload, so fewer than 10 actual API calls can trigger this detection. CloudTrail supplies a stable eventID for identifying duplicate deliveries; count distinct eventID values (or deduplicate on it) before applying the threshold.

Useful? React with 👍 / 👎.

@nasbench nasbench modified the milestones: v6.8.0, v6.9.0 Oct 5, 2026
….yml

Group EC2 key uploads by AWS identity and count unique API events

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants