Technique.View on attack.mitre.org
An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs.
Adversaries may attempt to discover information about the services enabled throughout the environment. Azure tools and APIs, such as the Microsoft Graph API and Azure Resource Manager API, can enumerate resources and services, including applications, management groups, resources and policy definitions, and their relationships that are accessible by an identity.
For example, Stormspotter is an open source tool for enumerating and constructing a graph for Azure resources and services, and Pacu is an open source AWS exploitation framework that supports several methods for discovering cloud services.
Adversaries may use the information gained to shape follow-on behaviors, such as targeting data or credentials from enumerated services or evading identified defenses through Disable or Modify Tools or Disable or Modify Cloud Log.
Rules on DetectionCode tagged with T1526.
| Rule | Level | Log source |
|---|---|---|
| Discovery Using AzureHound | high | azure / NULL |
| PUA - Seatbelt Execution | high | windows / process_creation |
| Github Self Hosted Runner Changes Detected | low | github / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Amazon EKS Kubernetes cluster scan detection | Hunting | NULL | |
| Amazon EKS Kubernetes Pod scan detection | Hunting | NULL | |
| ASL AWS Excessive Security Scanning | Anomaly | NULL | |
| AWS Excessive Security Scanning | TTP | NULL | AWS CloudTrail |
| Azure AD AzureHound UserAgent Detected | TTP | NULL | Azure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs |
| Azure AD Service Principal Enumeration | TTP | NULL | Azure Active Directory MicrosoftGraphActivityLogs |
| GCP Kubernetes cluster pod scan detection | Hunting | NULL | |
| GCP Kubernetes cluster scan detection | TTP | NULL | |
| Kubernetes Azure scan fingerprint | Hunting | NULL | |
| Kubernetes Scanner Image Pulling | TTP | NULL | |
| Kubernetes Suspicious Image Pulling | Anomaly | NULL | Kubernetes Audit |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupStorm-0501 | Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations. |
| ToolPacu | Pacu can enumerate AWS services, such as CloudTrail and CloudWatch. |
| ToolROADTools | ROADTools can enumerate Azure AD applications and service principals. |
| MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search GitHub for Actions runner processes. |
| ToolTruffleHog | TruffleHog has the ability to scan code repositories and CI/CD platforms. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.