AuthorizeSecurityGroupIngress
AuthorizeSecurityGroupIngress
Event
Adds inbound security-group rules. A broad source range permits matching traffic at the security-group layer; it does not by itself make the resource internet-reachable or authorize an application login.
Security Context
Unauthorized exposure of administrative ports can weaken defenses. Approved access changes also use this API. Inspect resource attachments, routing, network ACLs, and host authentication. A generic AWS CLI user agent does not establish use of a specific offensive tool.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: AuthorizeSecurityGroupIngress. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.groupId | Changed security group. |
requestParameters.ipPermissions | Sources, protocol, and port scope. |
responseElements.securityGroupRuleSet | New rule IDs and values, when recorded. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and request outcome, including dry-run and duplicate-rule errors.
- Identify attached network interfaces and compare the complete effective rule set before and after the change.
- Verify routes, public addressing, network ACLs, listening services, and authentication requirements.
- Correlate with CreateNetworkAclEntry and host login evidence. A key-pair creation event alone does not establish an installed SSH key on an existing instance.
Sample Event
Synthetic scenario. Draco requests TCP 22 from 0.0.0.0/0 on a fictional group. No successful SSH session, installed key, public route, or offensive-tool identity is demonstrated. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:21:53Z", "eventSource": "ec2.amazonaws.com", "eventName": "AuthorizeSecurityGroupIngress", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "groupId": "sg-0123456789abcdef0", "ipPermissions": { "items": [ { "ipProtocol": "tcp", "fromPort": 22, "toPort": 22, "groups": {}, "ipRanges": { "items": [ { "cidrIp": "0.0.0.0/0" } ] }, "ipv6Ranges": {}, "prefixListIds": {} } ] } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000001111010", "_return": true, "securityGroupRuleSet": { "items": [ { "securityGroupRuleId": "sgr-0abcdef0123456789", "groupOwnerId": "555123456789", "groupId": "sg-0123456789abcdef0", "isEgress": false, "ipProtocol": "tcp", "fromPort": 22, "toPort": 22, "cidrIpv4": "0.0.0.0/0" } ] } }, "requestID": "90000000-0000-4000-8000-000001111010", "eventID": "90000000-0000-4000-8000-000001111011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.