< Back to rules search
AWS EC2 Instance Outbound Connections to TOR
Set up the guardduty integration.
Detect when an EC2 instance makes an outbound network connection from TOR.
This rule lets you monitor this GuardDuty integration finding:
Triage & Response
- Determine if the EC2 instance should be making requests to TOR.
- If the instance is compromised:
- Review the AWS documentation on remediating a compromised EC2 instance.