Skip to content

Hide Navigation Hide TOC

AWS Key Pair Import Activity (92f84194-8d9a-4ee0-8699-c30bfac59780)

Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.

Cluster A Galaxy A Cluster B Galaxy B Level
AWS Key Pair Import Activity (92f84194-8d9a-4ee0-8699-c30bfac59780) Sigma-Rules Valid Accounts - T1078 (b17a1a56-e99c-403c-8948-561df0cffe81) Attack Pattern 1