[New Rule] AWS SES Identity Verified Then Deleted - #6658
Conversation
There was a problem hiding this comment.
Pull request overview
Adds a new AWS CloudTrail EQL sequence detection rule to identify a suspicious “verify SES identity → delete identity” pattern within 1 hour by the same AWS principal, aimed at catching SES abuse used for phishing/spam operations and subsequent cleanup.
Changes:
- Introduced a new EQL sequence rule for SES identity verification followed by deletion (maxspan 1h).
- Added investigation guide content, references, tags, and ATT&CK mappings for triage and classification.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Rule: New - GuidelinesThese guidelines serve as a reminder set of considerations when proposing a new rule. Documentation and Context
Rule Metadata Checks
New BBR Rules
Testing and Validation
|
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
terrancedejesus
left a comment
There was a problem hiding this comment.
LGTM. Agreed on dropping this to medium, verify-then-delete can be maintenance. Also +1 on the 30m maxspan being long for EQL.
…ied_then_deleted.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
…ied_then_deleted.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Updated the SES identity verification rule to reflect changes in the creation and updated dates, modified the detection window from one hour to 30 minutes, and switched the query language from EQL to ESQL.
There was a problem hiding this comment.
🟡 Changes recommended
The rule’s implementation (ES|QL + fixed 30-minute bucketing) and tagging currently conflict with the PR’s stated EQL sequence behavior and includes at least one tag likely to fail schema validation.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
Suppressed comments (1)
rules/integrations/aws/resource_development_ses_identity_verified_then_deleted.toml:30
- The PR description and “How To Test” section describe an EQL sequence with maxspan=1h, but this rule is implemented as an ES|QL aggregation with a 30-minute window (language/type set to esql and the note describes 30-minute aggregation). Please align the rule implementation with the PR description (or vice versa) so reviewers/users understand the actual detection semantics.
from = "now-35m"
interval = "30m"
language = "esql"
license = "Elastic License v2"
name = "AWS SES Email Identity Verified Then Deleted"
- Files reviewed: 1/1 changed files
- Comments generated: 2
- Review effort level: Lite
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Removed 'first_verify' and 'last_delete' from the list.
Pull Request
Issue link(s):
Summary - What I changed
Added an
eqlsequence rule that detects an SES email identity verified and then deleted by the same AWS identity within one hour — the verify-use-delete pattern used by adversaries to send phishing email from a victim account's SES capacity and then remove evidence of the sending domain.Why it matters
Amazon SES requires email addresses and domains to be verified before use as senders. An adversary who obtains SES write credentials can verify a domain they control, send bulk phishing email under the victim organization's SES reputation and sending quota, then delete the identity to remove it from
ListIdentitiesoutput — making post-incident attribution harder. The verify-then-delete sequence within a short window is a recognized attacker technique documented in SES abuse research, and has no common legitimate equivalent since test cleanup workflows typically operate on sandbox addresses over longer timeframes.How To Test
Query to verify in our TRaDE stack:
Checklist
Rule: NewContributor checklist