Skip to content

Create an EC2 Key Pair with a Suspicious Name

idempotent

Platform: AWS

Mappings

Description

Creates an EC2 key pair, simulating attackers planting their own key pair so they can later launch or access EC2 instances without relying on the credentials they used to gain initial access.

By default, the key pair is named key-stratus-red-team-, which matches a "key*" naming convention associated with attacker-planted key pairs while still being unique per detonation. To simulate a specific known suspicious name observed being reused across unrelated compromised AWS environments (such as xg1), set the STRATUS_RED_TEAM_KEY_PAIR environment variable to the desired key pair name.

Warm-up: None.

Detonation:

  • Call ec2:DescribeInstances filtered by the key name, to check whether the key pair is already in use.
  • Call ec2:CreateKeyPair to create a new key pair.

References:

Instructions

Detonate with Stratus Red Team
stratus detonate aws.persistence.ec2-create-suspicious-keypair

Detection

Identify calls to the CloudTrail event CreateKeyPair where requestParameters.keyName starts with key and the caller authenticated with an IAM user access key (userIdentity.accessKeyId starting with AKIA) — a known suspicious naming convention for attacker-planted key pairs, as opposed to a descriptive, project-scoped name.