Elastic medium stable kql
AWS Lambda Function High-Frequency Invocation by a Single Principal
Identifies a single principal directly invoking AWS Lambda functions at a high volume within a one-hour window. Adversaries may drive excessive invocations to abuse functions for resource hijacking or cryptomining, to inflate costs in a denial-of-wallet attack, or to enumerate function behavior. This is a volumetric heuristic: the threshold is environment-dependent and high-throughput applications can exceed it, so tune it to the deployment. This rule relies on AWS Lambda data event logging, which is not enabled by default.
Detection Logic
from logs-aws.cloudtrail-*
// Lambda invocation data events (data-plane; requires data event logging enabled)
| where
event.provider == "lambda.amazonaws.com"
and event.action like "Invoke*"
and event.outcome == "success"
and aws.cloudtrail.user_identity.arn IS NOT NULL
| stats
Esql.invocation_count = count(*),
Esql.source_ips = values(source.ip)
by
aws.cloudtrail.user_identity.arn
// Threshold is environment-dependent — tune to the deployment
| where Esql.invocation_count >= 1000
| keep
aws.cloudtrail.user_identity.arn,
Esql.invocation_count,
Esql.source_ips
| sort Esql.invocation_count desc False Positives
- ⚠ Legitimate high-throughput applications, batch jobs, load tests, and automation can invoke functions at high volume and will exceed any fixed threshold. Validate the principal in `aws.cloudtrail.user_identity.arn` and the workload context, and tune the threshold to the environment.
Field Validations
Loading…
Comments (0)
Loading comments...