AWS Rare Source AS Organization Activity
Surfaces an AWS identity whose successful API traffic is dominated by a small set of large cloud-provider source AS organization labels, yet also shows a very small share of traffic from other AS organization names—including at least one sensitive control-plane, credential, storage, or model-invocation action on that uncommon network path with recent activity from the uncommon path. The intent is to highlight disproportionate “baseline” cloud egress versus sparse use from rarer networks on the same principal, a shape that can appear when automation or CI credentials are reused or pivoted outside their usual hosted-cloud footprint.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/04/21"
3integration = ["aws"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Surfaces an AWS identity whose successful API traffic is dominated by a small set of large cloud-provider source AS
11organization labels, yet also shows a very small share of traffic from other AS organization names—including at least one
12sensitive control-plane, credential, storage, or model-invocation action on that uncommon network path with recent
13activity from the uncommon path. The intent is to highlight disproportionate “baseline” cloud egress versus sparse use
14from rarer networks on the same principal, a shape that can appear when automation or CI credentials are reused or
15pivoted outside their usual hosted-cloud footprint.
16"""
17false_positives = [
18 """
19 Global employees on VPNs, split DNS or proxy paths that change AS labels, regional carrier rebrands, or mobile
20 hotspots can produce a small non-cloud AS share on the same IAM user as hyperscaler- or SaaS-classified traffic.
21 Corporate travel, emergency break-glass from a home ISP, and multi-region runners may also widen AS diversity without
22 malice. Tune thresholds, add account or principal allowlists, or narrow the sensitive-action list after baseline review.
23 """,
24]
25from = "now-7d"
26interval = "1h"
27language = "esql"
28license = "Elastic License v2"
29name = "AWS Rare Source AS Organization Activity"
30note = """## Triage and analysis
31
32### Investigating AWS Rare Source AS Organization Activity After High Cloud-Provider Volume
33
34The rule aggregates roughly seven days of successful CloudTrail per `user.name` and `aws.cloudtrail.user_identity.type`.
35It expects a **high count** of events whose GeoIP AS organization matches a short allowlist of large cloud/SaaS providers,
36**at least one** event from a different AS organization, a **low ratio** of uncommon-network events to all events, few
37**distinct** uncommon AS labels, and **recent** uncommon-network timestamps. It further requires at least one
38**sensitive** API from an uncommon network (see query `event.action` list).
39
40#### Possible investigation steps
41
42- Compare `Esql.src_asn_values` to `Esql.user_agent_values` and map each `source.ip` (from raw CloudTrail) to expected
43 admin paths, pipelines, or offices.
44- Pivot on `user.name` and `aws.cloudtrail.user_identity.access_key_id` (from underlying events) for IAM, STS, S3, and
45 Secrets Manager activity around `Esql.most_recent_low_asn_day`.
46- Confirm whether the identity is meant for automation only; if so, rare human ISP ASNs warrant higher scrutiny.
47- Review `Esql.untrusted_suspicious_actions` for the mix of discovery versus privilege-changing APIs.
48
49### False positive analysis
50
51- **Threshold sensitivity**: Raise `Esql.trusted_cloud_event_count` or Lower `Esql.rare_asn_ratio` and `Esql.untrusted_event_count` if legitimate rare-ASN
52 noise persists.
53- **MongoDB / other allowlist labels**: Extend `is_trusted_cloud` if your approved automation consistently appears under
54 another legal-entity string.
55
56### Response and remediation
57
58- If abuse is plausible: rotate credentials for the principal, enforce OIDC or short-lived keys for automation, and
59 tighten IAM and data-plane permissions.
60
61### Additional information
62
63- [CloudTrail user identity](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference-user-identity.html)
64"""
65references = [
66 "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference.html",
67]
68risk_score = 73
69rule_id = "d1b37c0b-4f8b-4cfb-9a1d-639bf8c028b7"
70severity = "high"
71tags = [
72 "Domain: Cloud",
73 "Data Source: AWS",
74 "Data Source: Amazon Web Services",
75 "Data Source: AWS CloudTrail",
76 "Use Case: Threat Detection",
77 "Tactic: Initial Access",
78 "Resources: Investigation Guide",
79 "Noise: Low",
80 "Performance: Slow",
81 "Rule Type: ES|QL",
82 "Platform: AWS",
83]
84timestamp_override = "event.ingested"
85type = "esql"
86
87query = '''
88FROM logs-aws.cloudtrail-*
89| WHERE event.dataset == "aws.cloudtrail"
90 AND event.outcome == "success"
91 AND source.as.organization.name IS NOT NULL
92 AND user.name IS NOT NULL
93
94| EVAL is_trusted_cloud = CASE(
95 source.as.organization.name LIKE "Amazon*" OR
96 source.as.organization.name == "Google LLC" OR
97 source.as.organization.name == "Microsoft Corporation" OR
98 source.as.organization.name == "MongoDB, Inc.",
99 true, false
100 )
101
102| EVAL is_suspicious_action = CASE(
103 event.action IN (
104 "GetCallerIdentity", "GetAccountSummary", "ListAccountAliases",
105 "GetSecretValue", "ListSecrets", "DescribeSecret",
106 "GetParameter", "GetParameters", "GetParametersByPath",
107 "AssumeRole", "AssumeRoleWithWebIdentity", "AssumeRoleWithSAML",
108 "AttachUserPolicy", "AttachRolePolicy",
109 "PutUserPolicy", "PutRolePolicy",
110 "CreateAccessKey", "UpdateAccessKey",
111 "CreateUser", "CreateLoginProfile",
112 "UpdateLoginProfile", "AddUserToGroup",
113 "GetObject", "ListBuckets", "ListObjects", "ListObjectsV2",
114 "InvokeModel", "InvokeModelWithResponseStream", "Converse"
115 ), true, false
116 )
117
118// Single aggregation — full event count preserved for ratio logic
119// suspicious action tracking is additive on top
120| STATS
121 Esql.total_events_all_asns = COUNT(*),
122 Esql.count_distinct_asns = COUNT_DISTINCT(source.as.organization.name),
123 Esql.src_asn_values = VALUES(source.as.organization.name),
124 Esql.user_agent_values = VALUES(user_agent.original),
125 Esql.related_users = VALUES(user.changes.name),
126 Esql.source_ip_values = VALUES(source.address),
127 Esql.has_trusted_cloud_asn = MAX(is_trusted_cloud),
128 Esql.trusted_cloud_event_count = SUM(CASE(is_trusted_cloud == true, 1, 0)),
129 Esql.untrusted_event_count = SUM(CASE(is_trusted_cloud == false, 1, 0)),
130 // Suspicious action visibility from untrusted ASNs — informational only, not a filter
131 Esql.untrusted_suspicious_count = SUM(CASE(
132 is_trusted_cloud == false AND is_suspicious_action == true, 1, 0
133 )),
134 Esql.untrusted_suspicious_actions = VALUES(CASE(
135 is_trusted_cloud == false AND is_suspicious_action == true,
136 event.action, null
137 )),
138 Esql.most_recent_low_asn_day = MAX(CASE(
139 is_trusted_cloud == false, @timestamp, null
140 ))
141 BY user.name, aws.cloudtrail.user_identity.type
142
143| EVAL Esql.rare_asn_ratio = TO_DOUBLE(Esql.untrusted_event_count) / TO_DOUBLE(Esql.total_events_all_asns),
144 Esql.unique_action_from_untrusted_asn = MV_COUNT(Esql.untrusted_suspicious_actions)
145
146// Detection thresholds — unchanged, full event counts drive the logic
147| WHERE Esql.has_trusted_cloud_asn == true
148 AND Esql.untrusted_event_count >= 1
149 AND Esql.trusted_cloud_event_count >= 100
150 AND Esql.rare_asn_ratio <= 0.01
151 AND Esql.unique_action_from_untrusted_asn >= 2
152 AND Esql.count_distinct_asns <= 5
153 AND Esql.most_recent_low_asn_day >= NOW() - 1 hour
154
155| KEEP user.name,
156 aws.cloudtrail.user_identity.type,
157 Esql.*
158'''
159
160[rule.investigation_fields]
161field_names = [
162 "user.name",
163 "aws.cloudtrail.user_identity.type",
164 "Esql.*"
165]
166
167
168
169[[rule.threat]]
170framework = "MITRE ATT&CK"
171
172[[rule.threat.technique]]
173id = "T1078"
174name = "Valid Accounts"
175reference = "https://attack.mitre.org/techniques/T1078/"
176
177[[rule.threat.technique.subtechnique]]
178id = "T1078.004"
179name = "Cloud Accounts"
180reference = "https://attack.mitre.org/techniques/T1078/004/"
181
182[rule.threat.tactic]
183id = "TA0001"
184name = "Initial Access"
185reference = "https://attack.mitre.org/tactics/TA0001/"
Triage and analysis
Investigating AWS Rare Source AS Organization Activity After High Cloud-Provider Volume
The rule aggregates roughly seven days of successful CloudTrail per user.name and aws.cloudtrail.user_identity.type.
It expects a high count of events whose GeoIP AS organization matches a short allowlist of large cloud/SaaS providers,
at least one event from a different AS organization, a low ratio of uncommon-network events to all events, few
distinct uncommon AS labels, and recent uncommon-network timestamps. It further requires at least one
sensitive API from an uncommon network (see query event.action list).
Possible investigation steps
- Compare
Esql.src_asn_valuestoEsql.user_agent_valuesand map eachsource.ip(from raw CloudTrail) to expected admin paths, pipelines, or offices. - Pivot on
user.nameandaws.cloudtrail.user_identity.access_key_id(from underlying events) for IAM, STS, S3, and Secrets Manager activity aroundEsql.most_recent_low_asn_day. - Confirm whether the identity is meant for automation only; if so, rare human ISP ASNs warrant higher scrutiny.
- Review
Esql.untrusted_suspicious_actionsfor the mix of discovery versus privilege-changing APIs.
False positive analysis
- Threshold sensitivity: Raise
Esql.trusted_cloud_event_countor LowerEsql.rare_asn_ratioandEsql.untrusted_event_countif legitimate rare-ASN noise persists. - MongoDB / other allowlist labels: Extend
is_trusted_cloudif your approved automation consistently appears under another legal-entity string.
Response and remediation
- If abuse is plausible: rotate credentials for the principal, enforce OIDC or short-lived keys for automation, and tighten IAM and data-plane permissions.
Additional information
References
Related rules
- AWS Credentials Used from GitHub Actions and Non-CI/CD Infrastructure
- AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts
- AWS EC2 LOLBin Execution via SSM SendCommand
- AWS API Activity from Uncommon S3 Client by Rare User
- AWS Access Token Used from Multiple Addresses