Lateral movement

AWS GuardDuty detects brute force attempts on an exposed instance with lateral movement risks

Description

Brute force attempts were detected by AWS GuardDuty service on the Internet facing EC2 instance {AwsEc2Instance} ({AwsEc2Instance.InstanceId}) with lateral movement risks. AWS GuardDuty is a threat detection service that continuously monitors your AWS accounts and workloads for malicious activity. The service detects a type UnauthorizedAccess:EC2/SSHBruteForce brute force attempt on an EC2 instance that Orca has identified as exposed to the Internet and poses a danger of lateral movement.