Potential Destructive AWS CLI Command Executed by GenAI Agent

Last updated 15 days ago on 2026-09-14
Created 15 days ago on 2026-09-14

About

Identifies a cloud CLI command that destroys infrastructure or identities, such as terminating EC2 instances, removing S3 buckets, or deleting IAM users, when it is spawned by a GenAI coding agent directly or through the agent's shell wrapper. A compromised or prompt-injected agent can be steered into wiping the developer's environment and cloud account using the credentials it already holds, as seen in the malicious Amazon Q Developer for VS Code v1.84.0 release (AWS-2025-015).
Tags
Domain: EndpointDomain: CloudDomain: GenAIPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsPlatform: KubernetesOS: LinuxOS: macOSOS: WindowsService: AWS EC2Service: AWS S3Service: AWS IAMService: AWS RDSService: AWS LambdaTactic: ImpactTactic: Defense EvasionData Source: Elastic DefendRule Type: Custom Query (KQL)Mitre Atlas: T0051Language: kuery
Severity
high
Risk Score
73
MITRE ATT&CK™

Impact (TA0040)(external, opens in a new tab or window)

Defense Evasion (TA0005)(external, opens in a new tab or window)

False Positive Examples
Authorized infrastructure teardown automation may legitimately invoke these commands. Correlate with change management records and known deployment pipeline identities before escalating. Developers who explicitly instruct an agent to tear down a development environment or rotate access keys will trigger this rule. Confirm intent with the user before escalating.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-endpoint.events.process*
Related Integrations

endpoint(external, opens in a new tab or window)

Query
text code block:
event.category : "process" and event.type : "start" and event.action : (start or exec) and ( process.parent.name : ( qterm or qterm.exe or qchat or qchat.exe or kiro or "kiro-cli" or "kiro-cli-chat" or "kiro-cli-term" or kiro.exe or "kiro-cli.exe" or "kiro-cli-chat.exe" or "kiro-cli-term.exe" or claude or "claude-bin" or claude.exe or codex or codex.exe or copilot or copilot.exe or cursor or cursor.exe or "Cursor Helper (Plugin)" or "Cursor Helper" or "gemini-cli" or "gemini-cli.exe" or windsurf or windsurf.exe or aider or aider.exe or cline or goose or goose.exe or opencode or opencode.exe ) or process.parent.executable : ( */.local/bin/q or */usr/local/bin/q or *\\Users\\*\\AppData\\Local\\Programs\\Amazon Q\\q.exe or *\\Users\\*\\AppData\\Local\\Programs\\Amazon Q\\*\\q.exe or *\\Program Files\\Amazon Q\\q.exe or *\\Program Files\\Amazon Q\\*\\q.exe ) or ( process.parent.name : (bash or zsh or sh or dash or cmd.exe or powershell.exe or pwsh or pwsh.exe) and process.parent.command_line : ( */.claude/shell-snapshots/* or *\\.claude\\shell-snapshots\\* or */.codex/* or *\\.codex\\* or */.kiro/* or *\\.kiro\\* or */.aws/amazonq/* or *\\.aws\\amazonq\\* or */.goose/* or */.opencode/* or */.aider* ) ) ) and ( ( process.name : (aws or aws.exe) and process.command_line : ( *ec2 terminate-instances* or *ec2 delete-volume* or *ec2 delete-snapshot* or *s3 rb* or *s3 rm*--recursive* or *s3api delete-bucket* or *s3api delete-objects* or *iam delete-user* or *iam delete-role* or *iam delete-login-profile* or *iam delete-access-key* or *rds delete-db-instance* or *rds delete-db-cluster* or *dynamodb delete-table* or *efs delete-file-system* or *eks delete-cluster* or *ecs delete-cluster* or *lambda delete-function* or *kms schedule-key-deletion* or *cloudformation delete-stack* or *cloudtrail delete-trail* or *cloudtrail stop-logging* or *backup delete-recovery-point* or *organizations close-account* ) ) or ( process.name : (sam or sam.exe) and process.command_line : *sam delete* ) or ( process.name : (terraform or terraform.exe or tofu or tofu.exe) and process.command_line : *destroy*-auto-approve* ) or ( process.name : (kubectl or kubectl.exe) and process.command_line : (*delete*--all* or *delete namespace* or *delete ns*) ) ) and not process.args : ("--dry-run*" or "--help*" or "-help*" or "-h" or "help" or "--version*")

Install detection rules in Elastic Security

Detect Potential Destructive AWS CLI Command Executed by GenAI Agent in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).