2026 Critical Cloud Control Plane Detection: Interactive Cloud Shell Session Launched from Anomalous Identity or Geography
This rule detects the initialization of an AWS CloudShell environment or session where Multi-Factor Authentication (MFA) was not explicitly recorded in the event data. Unauthorized access to CloudShell can provide an adversary with a command-line interface to interact with AWS APIs, potentially facilitating further malicious activities.
Sigma

