How Identifying UserData Script Manipulation Accelerates Investigation
ID: e466a007-0ac7-52fa-97b7-ebfa8a326ace
STIX ID: report--e466a007-0ac7-52fa-97b7-ebfa8a326ace
Feed Name: Mitiga
This report explains how threat actors can manipulate EC2 UserData to run arbitrary scripts on instances—allowing immediate code execution, persistence, malware deployment, and exfiltration of instance IAM credentials via the metadata service. It details attack sequences (e.g., stop-modify-start), demonstrates credential exfiltration to an attacker-owned S3 bucket, highlights detection challenges with CloudTrail (which does not expose modified user data contents), and recommends monitoring and automated forensic approaches (including Mitiga IR² detections) to identify and investigate such abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
