Skip to content

StartSession

AWS

StartSession

service: AWS - SSM
techniques:

Event

Starts a session with a managed node. The selected document determines whether it provides a shell, SSH, or port forwarding; session creation alone is not a command transcript.

Security Context

Unauthorized remote administration can support cloud-tool execution or lateral movement (T1651/T1021). Ordinary support uses the same API. Do not infer shell commands solely from session lifecycle events.

Log Source

CloudTrail management event with eventSource: ssm.amazonaws.com and eventName: StartSession. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
target, documentName, parametersFor StartSession, node and session mode; recover these from the originating event when resuming.
sessionIdCorrelate the session lifecycle without parsing a node ID out of the session identifier.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Verify caller permissions, original session owner, target, selected document, and maintenance approval.
  3. Correlate start, resume, and termination records with managed-node evidence.
  4. Review configured S3/CloudWatch session logs where available. SSH and port-forwarding session content logging is unsupported; CloudTrail lifecycle records are not transcripts.

Sample Event

Synthetic scenario. The record illustrates session creation. It provides no command history or proof of subsequent host activity.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:58:24Z",
"eventSource": "ssm.amazonaws.com",
"eventName": "StartSession",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"target": "i-0123456789abcdef0"
},
"responseElements": {
"sessionId": "draco-0123456789abcdef0",
"tokenValue": "HIDDEN_DUE_TO_SECURITY_REASONS",
"streamUrl": "HIDDEN_DUE_TO_SECURITY_REASONS"
},
"requestID": "90000000-0000-4000-8000-000110110110",
"eventID": "90000000-0000-4000-8000-000110110111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Lateral Movement Execution

Techniques:
  • T1651 — Cloud Administration Command — Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.
  • T1021 — Remote Services — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.