Meta tags:
Headings (most frequently used words):
cloud, modify, compute, infrastructure, create, instance, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,
Text of the page (most frequently used words):
cloud (17), instance (14), the (13), all (11), #create (11), att (10), and (9), new (8), t1578 (8), enterprise (7), may (7), compute (7), data (6), instances (6), modify (6), within (6), ics (5), mobile (5), none (5), detection (5), techniques (5), for (5), creation (5), infrastructure (5), mitre (4), defenses (4), sub (4), scattered (4), spider (4), retrieved (4), created (4), account (4), version (4), adversary (4), 2026 (3), policy (3), cti (3), assets (3), mitigations (3), 2022 (3), 2020 (3), from (3), snapshot (3), iam (3), description (3), name (3), permissions (3), creating (3), with (3), users (3), has (3), environment (3), c0027 (3), 002 (3), corporation (2), are (2), use (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), tactics (2), matrices (2), core (2), objects (2), cisa (2), 2023 (2), november (2), advisory (2), march (2), 2024 (2), defender (2), targeting (2), organizations (2), events (2), used (2), can (2), strategy (2), analytic (2), limit (2), role (2), that (2), user (2), victim (2), virtual (2), access (2), lapsus (2), azure (2), technique (2), allow (2), more (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, cybersecurity, aa23, 320a, mstic, dart, m365, dev, 0537, criminal, actor, exfiltration, destruction, parisi, december, not, simulation, crowdstrike, investigations, reveal, intrusion, campaign, telco, bpo, companies, june, mandiant, february, trends, references, focuses, abnormal, unauthorized, perspective, suspicious, behavior, includes, rarely, newly, accounts, unusual, geolocations, rapid, sequences, followed, mounting, unexpected, network, changes, applied, indicate, adversarial, rather, than, legitimate, provisioning, an1242, det0449, accordance, least, privilege, should, number, organization, administrative, privileges, strive, reduce, permanent, privileged, assignments, conduct, periodic, entitlement, reviews, roles, policies, management, m1018, routinely, check, ensure, only, expected, have, capability, audit, m1047, mitigation, amazon, ec2, g1015, machines, target, after, leveraging, credential, g1004, during, tenant, vms, procedure, examples, live, permalink, last, modified, arun, seelagan, contributors, iaas, platforms, defense, impairment, tactic, also, carry, out, malicious, activity, without, affecting, execution, current, running, machine, service, evade, bypass, firewall, rules, exist, currently, residing, one, volumes, mount, snapshots, then, apply, less, restrictive, security, collect, remote, staging, local, system, configurations, 005, revert, 004, delete, 003, 001, other, home, open, join, october, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, council, learn, about, get, started, detections,
Text of the page (random words):
modify cloud compute infrastructure create cloud instance sub technique t1578 002 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise modify cloud compute infrastructure create cloud instance modify cloud compute infrastructure create cloud instance other sub techniques of modify cloud compute infrastructure 5 id name t1578 001 create snapshot t1578 002 create cloud instance t1578 003 delete cloud instance t1578 004 revert cloud instance t1578 005 modify cloud compute configurations an adversary may create a new instance or virtual machine vm within the compute service of a cloud account to evade defenses creating a new instance may allow an adversary to bypass firewall rules and permissions that exist on instances currently residing within an account an adversary may create snapshot of one or more volumes in an account create a new instance mount the snapshots and then apply a less restrictive security policy to collect data from local system or for remote data staging 1 creating a new instance may also allow an adversary to carry out malicious activity within an environment without affecting the execution of current running instances id t1578 002 sub technique of t1578 ⓘ tactic defense impairment ⓘ platforms iaas contributors arun seelagan cisa version 2 0 created 14 may 2020 last modified 12 may 2026 version permalink live version procedure examples id name description c0027 c0027 during c0027 scattered spider used access to the victim s azure tenant to create azure vms 2 g1004 lapsus lapsus has created new virtual machines within the target s cloud environment after leveraging credential access to cloud assets 3 g1015 scattered spider scattered spider has created amazon ec2 instances within the victim s environment 4 mitigations id mitigation description m1047 audit routinely check user permissions to ensure only the expected users have the capability to create new instances m1018 user account management limit permissions for creating new instances in accordance with least privilege organizations should limit the number of users within the organization with an iam role that has administrative privileges strive to reduce all permanent privileged role assignments and conduct periodic entitlement reviews on iam users roles and policies 1 detection strategy id name analytic id analytic description det0449 detection strategy for modify cloud compute infrastructure create cloud instance an1242 detection focuses on abnormal or unauthorized cloud instance creation events from a defender s perspective suspicious behavior includes vm instance creation by rarely used or newly created accounts creation events from unusual geolocations or rapid sequences of snapshot creation followed by instance creation and mounting unexpected network or iam policy changes applied to new instances can indicate adversarial use rather than legitimate provisioning references mandiant 2020 february m trends 2020 retrieved november 17 2024 parisi t 2022 december 2 not a simulation crowdstrike investigations reveal intrusion campaign targeting telco and bpo companies retrieved june 30 2023 mstic dart m365 defender 2022 march 24 dev 0537 criminal actor targeting organizations for data exfiltration and destruction retrieved may 17 2022 cisa 2023 november 16 cybersecurity advisory scattered spider aa23 320a retrieved march 18 2024 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|