Create an EC2 Key Pair with a Suspicious Name
idempotent
Platform: AWS
Mappings
-
MITRE ATT&CK
- Persistence
-
Threat Technique Catalog for AWS:
Description
Creates an EC2 key pair, simulating attackers planting their own key pair so they can later launch or access EC2 instances without relying on the credentials they used to gain initial access.
By default, the key pair is named key-stratus-red-team-, which
matches a "key*" naming convention associated with attacker-planted key pairs while still being
unique per detonation. To simulate a specific known suspicious name observed being reused across
unrelated compromised AWS environments (such as xg1), set the STRATUS_RED_TEAM_KEY_PAIR
environment variable to the desired key pair name.
Warm-up: None.
Detonation:
- Call ec2:DescribeInstances filtered by the key name, to check whether the key pair is already in use.
- Call ec2:CreateKeyPair to create a new key pair.
References:
Instructions
Detection
Identify calls to the CloudTrail event CreateKeyPair where requestParameters.keyName
starts with key and the caller authenticated with an IAM user access key
(userIdentity.accessKeyId starting with AKIA) — a known suspicious
naming convention for attacker-planted key pairs, as opposed to a descriptive, project-scoped name.