Lambda layer imported from external account

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Detected an external account adding lambda layer, which attackers could use to inject a backdoor inside the lambda function. If this is the case, make sure to remove the layer from the function.

Attribute Value
Type Hunting Query
Solution Amazon Web Services
ID 77d0aadc-aaea-4346-b61a-bf7ac6b71bba
Severity Medium
Tactics Persistence
Techniques T1525
Required Connectors AWS
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AWSCloudTrail EventName startswith "CreateFunction"
EventName startswith "UpdateFunctionConfiguration"
?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Amazon Web Services