StartSession
StartSession
Event
Starts a session with a managed node. The selected document determines whether it provides a shell, SSH, or port forwarding; session creation alone is not a command transcript.
Security Context
Unauthorized remote administration can support cloud-tool execution or lateral movement (T1651/T1021). Ordinary support uses the same API. Do not infer shell commands solely from session lifecycle events.
Log Source
CloudTrail management event with eventSource: ssm.amazonaws.com and eventName: StartSession. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
target, documentName, parameters | For StartSession, node and session mode; recover these from the originating event when resuming. |
sessionId | Correlate the session lifecycle without parsing a node ID out of the session identifier. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Verify caller permissions, original session owner, target, selected document, and maintenance approval.
- Correlate start, resume, and termination records with managed-node evidence.
- Review configured S3/CloudWatch session logs where available. SSH and port-forwarding session content logging is unsupported; CloudTrail lifecycle records are not transcripts.
Sample Event
Synthetic scenario. The record illustrates session creation. It provides no command history or proof of subsequent host activity.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:58:24Z", "eventSource": "ssm.amazonaws.com", "eventName": "StartSession", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "target": "i-0123456789abcdef0" }, "responseElements": { "sessionId": "draco-0123456789abcdef0", "tokenValue": "HIDDEN_DUE_TO_SECURITY_REASONS", "streamUrl": "HIDDEN_DUE_TO_SECURITY_REASONS" }, "requestID": "90000000-0000-4000-8000-000110110110", "eventID": "90000000-0000-4000-8000-000110110111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Lateral Movement Execution
- T1651 — Cloud Administration Command — Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.
- T1021 — Remote Services — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.