Skip to content

Hide Navigation Hide TOC

SSRF AWS Instance Metadata Endpoint Access - ATR-2026-01605 (99e47e34-fd7e-5adc-af3c-f0ce43a46314)

Detects SSRF (Server-Side Request Forgery) attempts targeting the AWS EC2 Instance Metadata Service (IMDS) at 169.254.169.254. When an agent's HTTP-fetch tool is redirected to this address, the agent retrieves IAM security credentials, instance identity documents, and other sensitive cloud configuration data accessible only from within the instance. This is the most impactful SSRF target in cloud-hosted agent deployments. Also detects the AWS IMDSv2 token endpoint at the same address.

Cluster A Galaxy A Cluster B Galaxy B Level
SSRF AWS Instance Metadata Endpoint Access - ATR-2026-01605 (99e47e34-fd7e-5adc-af3c-f0ce43a46314) Agent Threat Rules Cloud Instance Metadata API - T1552.005 (19bf235b-8620-4997-b5b4-94e0659ed7c3) Attack Pattern 1
SSRF AWS Instance Metadata Endpoint Access - ATR-2026-01605 (99e47e34-fd7e-5adc-af3c-f0ce43a46314) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern Cloud Instance Metadata API - T1552.005 (19bf235b-8620-4997-b5b4-94e0659ed7c3) Attack Pattern 2