AWS CloudShell
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS CloudShell rules that match the service but not a specific eventName. | N | N |
| Create | Creates a new AWS CloudShell environment, provisioning a pre-authenticated browser-based shell session with AWS CLI access. | N | Y |
any: AWS CloudShell (catch-all)
#Description
Catch-all entry for AWS CloudShell rules that match the service but not a specific eventName.
CreateEnvironment
#Description
Creates a new AWS CloudShell environment, provisioning a pre-authenticated browser-based shell session with AWS CLI access.
Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
event.action | 1 detection rule | Elastic |
event.outcome | 1 detection rule | Elastic |
event.provider | 1 detection rule | Elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1059, T1059.009, T1078, T1078.004