Potential Destructive AWS CLI Command Executed by GenAI Agent
editPotential Destructive AWS CLI Command Executed by GenAI Agent
editIdentifies a cloud CLI command that destroys infrastructure or identities, such as terminating EC2 instances, removing S3 buckets, or deleting IAM users, when it is spawned by a GenAI coding agent directly or through the agent’s shell wrapper. A compromised or prompt-injected agent can be steered into wiping the developer’s environment and cloud account using the credentials it already holds, as seen in the malicious Amazon Q Developer for VS Code v1.84.0 release (AWS-2025-015).
Rule type: query
Rule indices:
- logs-endpoint.events.process*
Severity: high
Risk score: 73
Runs every: 5m
Searches indices from: now-9m (Date Math format, see also Additional look-back time)
Maximum alerts per execution: 100
References:
- https://aws.amazon.com/security/security-bulletins/AWS-2025-015/
- https://github.com/aws/aws-toolkit-vscode/security/advisories/GHSA-7g7f-ff96-5gcw
- https://www.theregister.com/2025/07/24/amazon_q_ai_prompt/
- https://www.pointguardai.com/blog/clean-to-factory-state-the-ai-prompt-that-nearly-wiped-aws-accounts
Tags:
- Domain: Endpoint
- Domain: Cloud
- Domain: GenAI
- Platform: AWS
- Platform: Linux
- Platform: macOS
- Platform: Windows
- Platform: Kubernetes
- OS: Linux
- OS: macOS
- OS: Windows
- Service: AWS EC2
- Service: AWS S3
- Service: AWS IAM
- Service: AWS RDS
- Service: AWS Lambda
- Tactic: Impact
- Tactic: Defense Evasion
- Data Source: Elastic Defend
- Rule Type: Custom Query (KQL)
- Resources: Investigation Guide
- Mitre Atlas: T0051
Version: 1
Rule authors:
- Elastic
Rule license: Elastic License v2
Investigation guide
editTriage and analysis
Investigating Potential Destructive AWS CLI Command Executed by GenAI Agent
This rule detects a GenAI coding agent spawning a cloud CLI command that destroys infrastructure or identities. A compromised or prompt-injected agent can be steered into wiping the developer’s AWS account without any separate credential theft step, since the agent already holds the developer’s credentials. The malicious Amazon Q Developer pull request in July 2025 (AWS-2025-015) is the canonical real-world example of this attack pattern.
Possible investigation steps
- Identify the GenAI agent parent process and determine whether it was running in an autonomous or interactive mode at the time of the alert.
-
Review the full CLI command arguments to assess the scope of the destruction (resource IDs,
--recursiveflags, etc.). - Check for a preceding unusual or injected prompt in the agent’s context, such as content from a recently cloned repository, an opened file, or a web fetch result.
- Query AWS CloudTrail for the corresponding API call and confirm whether the destructive action was actually executed or was blocked.
- Determine if the user initiated the teardown intentionally or if it was triggered autonomously.
False positive analysis
- Authorized infrastructure teardown automation invoked through a GenAI interface may legitimately trigger this rule. Correlate with change management records and known deployment pipeline identities before escalating.
- Developers who explicitly instruct a GenAI agent to clean up development environments will generate alerts for legitimate use.
Response and remediation
- Initiate the incident response process based on the outcome of the triage.
- If the destructive command executed, immediately assess which resources were deleted and begin recovery from backups or infrastructure-as-code.
- Revoke the developer’s AWS credentials and rotate them after confirming the scope of the compromise.
- Review the agent’s recent conversation history and any external content it processed to identify the prompt injection source.
- Apply IAM permission boundaries on developer credentials to restrict the blast radius of future incidents.
Setup
editSetup
This rule requires data coming in from Elastic Defend.
Elastic Defend Integration Setup
Elastic Defend is integrated into the Elastic Agent using Fleet. Upon configuration, the integration allows the Elastic Agent to monitor events on your host and send data to the Elastic Security app.
Prerequisite Requirements:
- Fleet is required for Elastic Defend.
- To configure Fleet Server refer to the documentation.
The following steps should be executed in order to add the Elastic Defend integration:
- Go to the Kibana home page and click "Add integrations".
- In the query bar, search for "Elastic Defend" and select the integration to see more details about it.
- Click "Add Elastic Defend".
- Configure the integration name and optionally add a description.
- Select the type of environment you want to protect, either "Traditional Endpoints" or "Cloud Workloads".
- Enter a name for the agent policy in "New agent policy name". If other agent policies already exist, you can click the "Existing hosts" tab and select an existing policy instead.
- Click "Save and Continue".
- To complete the integration, select "Add Elastic Agent to your hosts" and install Elastic Agent on your hosts. For more details on Elastic Defend refer to the helper guide.
Rule query
editevent.category : "process" and event.type : "start" and event.action : (start or exec) and
(
process.parent.name : (
qterm or qterm.exe or qchat or qchat.exe or
kiro or "kiro-cli" or "kiro-cli-chat" or "kiro-cli-term" or
kiro.exe or "kiro-cli.exe" or "kiro-cli-chat.exe" or "kiro-cli-term.exe" or
claude or "claude-bin" or claude.exe or codex or codex.exe or
copilot or copilot.exe or cursor or cursor.exe or "Cursor Helper (Plugin)" or "Cursor Helper" or
"gemini-cli" or "gemini-cli.exe" or windsurf or windsurf.exe or
aider or aider.exe or cline or goose or goose.exe or opencode or opencode.exe
) or
process.parent.executable : (
*/.local/bin/q or */usr/local/bin/q or
*\\Users\\*\\AppData\\Local\\Programs\\Amazon Q\\q.exe or
*\\Users\\*\\AppData\\Local\\Programs\\Amazon Q\\*\\q.exe or
*\\Program Files\\Amazon Q\\q.exe or
*\\Program Files\\Amazon Q\\*\\q.exe
) or
(
process.parent.name : (bash or zsh or sh or dash or cmd.exe or powershell.exe or pwsh or pwsh.exe) and
process.parent.command_line : (
*/.claude/shell-snapshots/* or *\\.claude\\shell-snapshots\\* or
*/.codex/* or *\\.codex\\* or
*/.kiro/* or *\\.kiro\\* or
*/.aws/amazonq/* or *\\.aws\\amazonq\\* or
*/.goose/* or */.opencode/* or */.aider*
)
)
) and
(
(
process.name : (aws or aws.exe) and
process.command_line : (
*ec2 terminate-instances* or *ec2 delete-volume* or *ec2 delete-snapshot* or
*s3 rb* or *s3 rm*--recursive* or *s3api delete-bucket* or *s3api delete-objects* or
*iam delete-user* or *iam delete-role* or *iam delete-login-profile* or *iam delete-access-key* or
*rds delete-db-instance* or *rds delete-db-cluster* or *dynamodb delete-table* or
*efs delete-file-system* or *eks delete-cluster* or *ecs delete-cluster* or
*lambda delete-function* or *kms schedule-key-deletion* or
*cloudformation delete-stack* or
*cloudtrail delete-trail* or *cloudtrail stop-logging* or
*backup delete-recovery-point* or *organizations close-account*
)
) or
(
process.name : (sam or sam.exe) and process.command_line : *sam delete*
) or
(
process.name : (terraform or terraform.exe or tofu or tofu.exe) and
process.command_line : *destroy*-auto-approve*
) or
(
process.name : (kubectl or kubectl.exe) and
process.command_line : (*delete*--all* or *delete namespace* or *delete ns*)
)
) and not process.args : ("--dry-run*" or "--help*" or "-help*" or "-h" or "help" or "--version*")
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Impact
- ID: TA0040
- Reference URL: https://attack.mitre.org/tactics/TA0040/
-
Technique:
- Name: Data Destruction
- ID: T1485
- Reference URL: https://attack.mitre.org/techniques/T1485/
-
Technique:
- Name: Account Access Removal
- ID: T1531
- Reference URL: https://attack.mitre.org/techniques/T1531/
-
Tactic:
- Name: Defense Evasion
- ID: TA0005
- Reference URL: https://attack.mitre.org/tactics/TA0005/
-
Technique:
- Name: Impair Defenses
- ID: T1562
- Reference URL: https://attack.mitre.org/techniques/T1562/
-
Sub-technique:
- Name: Disable or Modify Cloud Logs
- ID: T1562.008
- Reference URL: https://attack.mitre.org/techniques/T1562/008/