{"id":"a840e606-7c8c-4684-9bc1-eb6b6155127f","title":"PUA - AWS TruffleHog Execution","description":"Detects the execution of TruffleHog, a popular open-source tool used for scanning repositories for secrets and sensitive information, within an AWS environment.\nIt has been reported to be used by threat actors for credential harvesting. All detections should be investigated to determine if the usage is authorized by security teams or potentially malicious.\n","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-10-21","modified":"","tags":["attack.credential-access","attack.t1555","attack.t1003"],"technique_ids":["T1003","T1555"],"logsource":{"product":"aws","service":"cloudtrail"},"falsepositives":["Legitimate use of TruffleHog by security teams for credential scanning."],"references":["https://github.com/trufflesecurity/trufflehog","https://www.rapid7.com/blog/post/tr-crimson-collective-a-new-threat-group-observed-operating-in-the-cloud/"],"source_path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_pua_trufflehog.yml","source_sha256":"a31d1b5e4a0d72541713198315e83047a4a9cbd5a74fcedf363ec1516badb47b","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/aws/cloudtrail/aws_cloudtrail_pua_trufflehog.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: PUA - AWS TruffleHog Execution\nid: a840e606-7c8c-4684-9bc1-eb6b6155127f\nstatus: experimental\ndescription: |\n    Detects the execution of TruffleHog, a popular open-source tool used for scanning repositories for secrets and sensitive information, within an AWS environment.\n    It has been reported to be used by threat actors for credential harvesting. All detections should be investigated to determine if the usage is authorized by security teams or potentially malicious.\nreferences:\n    - https://github.com/trufflesecurity/trufflehog\n    - https://www.rapid7.com/blog/post/tr-crimson-collective-a-new-threat-group-observed-operating-in-the-cloud/\nauthor: Swachchhanda Shrawan Poudel (Nextron Systems)\ndate: 2025-10-21\ntags:\n    - attack.credential-access\n    - attack.t1555\n    - attack.t1003\nlogsource:\n    product: aws\n    service: cloudtrail\ndetection:\n    selection:\n        userAgent: 'TruffleHog'\n    condition: selection\nfalsepositives:\n    - Legitimate use of TruffleHog by security teams for credential scanning.\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1003","id":"T1003","name":"OS Credential Dumping","page":"techniques/enterprise/T1003/"},{"key":"enterprise/T1555","id":"T1555","name":"Credentials from Password Stores","page":"techniques/enterprise/T1555/"}],"data_path":"data/detection-rules/a840e606-7c8c-4684-9bc1-eb6b6155127f.json","kind":"sigma"}
