If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1021/008 - Remote Services: Direct Cloud .

site address: attack.mitre.org/techniques/T1021/008 redirected to: attack.mitre.org/techniques/T1021/008

site title: Remote Services: Direct Cloud VM Connections, Sub-technique T1021.008 - Enterprise MITRE ATT&CK®

Our opinion (on Friday 21 August 2026 0:30:18 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

remote, services, direct, cloud, vm, connections, mitigations, detection, strategy, references, other, sub, techniques, of,

Text of the page (most frequently used words):
cloud (17), t1021 (11), the (10), att (10), all (10), 2023 (10), #direct (8), access (8), connections (8), enterprise (7), june (7), methods (7), console (6), native (6), remote (6), and (5), ics (5), mobile (5), none (5), techniques (5), serial (5), retrieved (5), aws (5), these (5), services (5), mitre (4), are (4), detection (4), sub (4), may (4), azure (4), connect (4), virtual (4), infrastructure (4), for (4), version (4), cti (3), data (3), mitigations (3), defenses (3), system (3), ec2 (3), instance (3), via (3), 008 (3), through (3), can (3), 2026 (2), corporation (2), use (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), microsoft (2), manager (2), september (2), october (2), hosted (2), command (2), execution (2), analytic (2), description (2), name (2), compute (2), management (2), disable (2), technique (2), adversaries (2), directly (2), ssh (2), with (2), windows (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, mandiant, intelligence, sim, swapping, abuse, part, well, balanced, attack, what, ian, ahl, lucr, scattered, spider, getting, saas, using, 2022, references, login, machines, ssm, followed, privilege, escalation, an0594, det0211, strategy, limit, which, users, allowed, user, account, m1018, machine, not, required, administrative, connection, types, where, feasible, remove, feature, program, m1042, mitigation, live, permalink, april, 2025, last, modified, created, thanabodi, phrakhun, naikordian, contributors, iaas, platforms, lateral, movement, tactic, utilize, pivot, environment, typically, provide, rather, than, scripts, administration, authentication, include, passwords, application, tokens, keys, default, allow, privileged, host, root, level, leverage, log, into, accessible, many, providers, offer, interactive, that, accessed, such, api, valid, accounts, 007, 006, vnc, 005, 004, distributed, component, object, model, 003, smb, admin, shares, 002, desktop, protocol, 001, other, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
remote services direct cloud vm connections sub technique t1021 008 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise remote services direct cloud vm connections remote services direct cloud vm connections other sub techniques of remote services 8 id name t1021 001 remote desktop protocol t1021 002 smb windows admin shares t1021 003 distributed component object model t1021 004 ssh t1021 005 vnc t1021 006 windows remote management t1021 007 cloud services t1021 008 direct cloud vm connections adversaries may leverage valid accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods many cloud providers offer interactive connections to virtual infrastructure that can be accessed through the cloud api such as azure serial console 1 aws ec2 instance connect 2 3 and aws system manager 4 methods of authentication for these connections can include passwords application access tokens or ssh keys these cloud native methods may by default allow for privileged access on the host with system or root level access adversaries may utilize these cloud native methods to directly access virtual infrastructure and pivot through an environment 5 these connections typically provide direct console access to the vm rather than the execution of scripts i e cloud administration command id t1021 008 sub technique of t1021 ⓘ tactic lateral movement ⓘ platforms iaas contributors thanabodi phrakhun naikordian version 1 0 created 02 june 2023 last modified 15 april 2025 version permalink live version mitigations id mitigation description m1042 disable or remove feature or program if direct virtual machine connections are not required for administrative use disable these connection types where feasible m1018 user account management limit which users are allowed to access compute infrastructure via cloud native methods detection strategy id name analytic id analytic description det0211 detection of direct vm console access via cloud native methods an0594 direct login to cloud hosted virtual machines via cloud native access methods e g ec2 instance connect azure serial console ssm followed by command execution or privilege escalation on the vm references microsoft 2022 october 17 azure serial console retrieved june 2 2023 aws 2023 june 2 connect using ec2 instance connect retrieved june 2 2023 ian ahl 2023 september 20 lucr 3 scattered spider getting saas y in the cloud retrieved september 20 2023 aws 2023 june 2 what is aws system manager retrieved june 2 2023 mandiant intelligence 2023 may 16 sim swapping and abuse of the microsoft azure serial console serial is part of a well balanced attack retrieved june 2 2023 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 57 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-57


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1021/008
X-GitHub-Request-Id C78C:3E43AC:11D1B8A:11F00A8:6A879C1A
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Fri, 21 Aug 2026 00:30:18 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290046-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787272218.453946,VS0,VE94
Vary Accept-Encoding
X-Fastly-Request-ID 55356504ba90daf6b327063909d812717915d7ee
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1021/008/
access-control-allow-origin *
expires Fri, 21 Aug 2026 00:40:18 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id FADA:D15A0:117EA57:119CE73:6A879C1A
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 00:30:18 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290048-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787272219.574997,VS0,VE102
vary Accept-Encoding
x-fastly-request-id 503fb90805292ab9e97b7c7d663d32fdd3eb6e11
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-b396
expires Fri, 21 Aug 2026 00:40:18 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 39FA:321A:113226C:114FCDE:6A879C1A
x-github-edge-region fra
accept-ranges bytes
age 0
date Fri, 21 Aug 2026 00:30:18 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290048-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787272219.685073,VS0,VE101
vary Accept-Encoding
x-fastly-request-id f2f9b091a85e8ee7d0baa607d64e7580c002b68e
content-length 7393

Meta Tags

title="Remote Services: Direct Cloud VM Connections, Sub-technique T1021.008 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size7393
load time (s)0.564972
redirect count2
speed download13108
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"