AWS Threat Hunting Ideas: Lambda
Overview
1. Unauthorized Lambda Function Creation (CreateFunction)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=CreateFunction
2. Function Modifications (UpdateFunctionConfiguration)
aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=UpdateFunctionConfiguration
3. Execution Role Abuse (AddPermission/RemovePermission)
4. Suspicious Function Invocation (InvokeFunction)
5. Data Exfiltration via Environment Variables (GetFunctionConfiguration)
6. Snapshot of Lambda Code (GetFunction/UpdateFunctionCode)
7. IAM Role Modification for Lambda Functions (AttachRolePolicy/DetachRolePolicy)
8. Event Source Manipulation (UpdateEventSourceMapping)
9. Disabling Function Tracing (DeleteFunctionEventInvokeConfig)
10. Deleting Lambda Functions (DeleteFunction)
Last updated