AuthorizeSecurityGroupEgress
AuthorizeSecurityGroupEgress
Event
Adds outbound security-group rules for specified destinations, protocols, and ports. Determine the effect from the combined rules on affected network interfaces and the rest of the network path.
Security Context
Unauthorized expansion may prepare a path for outbound activity, while approved service connectivity is routine. A security-group allow rule does not override network ACLs or routing. This event does not show a data transfer or establish which protocol carried one.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: AuthorizeSecurityGroupEgress. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.groupId | Changed security group. |
requestParameters.ipPermissions | Destination ranges or references, protocols, and ports. |
responseElements.securityGroupRuleSet | Created rule IDs and configuration, when present. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect errors or dry-run status before treating the request as a change.
- Compare previous and current rules, including other security groups on affected interfaces; assess whether the new rule expands effective access.
- Check routes, network ACLs, and destination controls for the actual outbound path.
- Correlate with AuthorizeSecurityGroupIngress and network/application evidence before concluding data left the environment.
Sample Event
Synthetic scenario. Draco requests outbound TCP 443 to all IPv4 destinations on a fictional group. The earlier restrictive configuration is an assumption, not shown here. This does not bypass a network ACL or demonstrate transfer. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:14:08Z", "eventSource": "ec2.amazonaws.com", "eventName": "AuthorizeSecurityGroupEgress", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "groupId": "sg-0123456789abcdef0", "ipPermissions": { "items": [ { "ipProtocol": "tcp", "fromPort": 443, "toPort": 443, "groups": {}, "ipRanges": { "items": [ { "cidrIp": "0.0.0.0/0" } ] }, "ipv6Ranges": {}, "prefixListIds": {} } ] } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000001111000", "_return": true, "securityGroupRuleSet": { "items": [ { "securityGroupRuleId": "sgr-0123456789abcdef0", "groupOwnerId": "555123456789", "groupId": "sg-0123456789abcdef0", "isEgress": true, "ipProtocol": "tcp", "fromPort": 443, "toPort": 443, "cidrIpv4": "0.0.0.0/0" } ] } }, "requestID": "90000000-0000-4000-8000-000001111000", "eventID": "90000000-0000-4000-8000-000001111001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.