For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-g55.md. A documentation index is available at /llms.txt.

Amazon EC2 AMI exfiltration attempt by IAM user

Goal

Detect a user attempting to exfiltrate an Amazon EC2 AMI Snapshot.

Strategy

This rule lets you monitor the ModifyImageAttribute CloudTrail API calls to detect when an Amazon EC2 AMI snapshot is made public or shared with an AWS account.

Making an AMI public is covered for calls made by an IAM user, an assumed role, a federated session, or the account root, since credential compromise most often surfaces as temporary session credentials rather than long-lived IAM user keys. Sharing an AMI with a specific AWS account remains scoped to IAM users, because automated cross-account image distribution runs almost entirely under assumed roles and would dominate that case. Calls invoked by the AWS Backup and EC2 Image Builder service principals are excluded as expected automation.

This rule also inspects:

  • @requestParameters.launchPermission.add.items.group array to determine if the string all is contained. This is the indicator which means the RDS snapshot is made public.
  • @requestParameters.launchPermission.add.items.userId array to determine if the string * is contained. This is the indicator which means the RDS snapshot was shared with a new or unknown AWS account.

Triage and response

  1. Confirm if the user: {{@userIdentity.arn}} intended to make the RDS snaphsot public.
  2. If the user did not make the API call:
    • Rotate the credentials.
    • Investigate if the same credentials made other unauthorized API calls.

Changelog

  • 10 August 2026 - Broadened the identity gate on ec2_ami_made_public_by_iam_user from @userIdentity.type:IAMUser to (IAMUser OR AssumedRole OR FederatedUser OR Root). The exfiltration indicators are identity-agnostic, and the previous gate missed the assumed-role sessions that some credential compromises utilize. Changed groupByFields on both queries from @userIdentity.userName to @userIdentity.arn. CloudTrail does not populate userIdentity.userName for AssumedRole, FederatedUser, or unaliased Root identities, so the widened made_public case would not have produced signals without this change. For IAM users the two fields are equivalent within an account, and @userIdentity.arn additionally distinguishes identically named users across accounts. It is present for all four identity types and matches the triage text and the sibling rule AWS AMI Made Public.