Skip to content

AuthorizeSecurityGroupIngress

AWS

AuthorizeSecurityGroupIngress

service: AWS - EC2
techniques:

Event

Adds inbound security-group rules. A broad source range permits matching traffic at the security-group layer; it does not by itself make the resource internet-reachable or authorize an application login.

Security Context

Unauthorized exposure of administrative ports can weaken defenses. Approved access changes also use this API. Inspect resource attachments, routing, network ACLs, and host authentication. A generic AWS CLI user agent does not establish use of a specific offensive tool.

T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: AuthorizeSecurityGroupIngress. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.

Key Fields

FieldInvestigation use
requestParameters.groupIdChanged security group.
requestParameters.ipPermissionsSources, protocol, and port scope.
responseElements.securityGroupRuleSetNew rule IDs and values, when recorded.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm approval and request outcome, including dry-run and duplicate-rule errors.
  2. Identify attached network interfaces and compare the complete effective rule set before and after the change.
  3. Verify routes, public addressing, network ACLs, listening services, and authentication requirements.
  4. Correlate with CreateNetworkAclEntry and host login evidence. A key-pair creation event alone does not establish an installed SSH key on an existing instance.

Sample Event

Synthetic scenario. Draco requests TCP 22 from 0.0.0.0/0 on a fictional group. No successful SSH session, installed key, public route, or offensive-tool identity is demonstrated. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:21:53Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "AuthorizeSecurityGroupIngress",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"groupId": "sg-0123456789abcdef0",
"ipPermissions": {
"items": [
{
"ipProtocol": "tcp",
"fromPort": 22,
"toPort": 22,
"groups": {},
"ipRanges": {
"items": [
{
"cidrIp": "0.0.0.0/0"
}
]
},
"ipv6Ranges": {},
"prefixListIds": {}
}
]
}
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000001111010",
"_return": true,
"securityGroupRuleSet": {
"items": [
{
"securityGroupRuleId": "sgr-0abcdef0123456789",
"groupOwnerId": "555123456789",
"groupId": "sg-0123456789abcdef0",
"isEgress": false,
"ipProtocol": "tcp",
"fromPort": 22,
"toPort": 22,
"cidrIpv4": "0.0.0.0/0"
}
]
}
},
"requestID": "90000000-0000-4000-8000-000001111010",
"eventID": "90000000-0000-4000-8000-000001111011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.