Modify Cloud Compute Infrastructure

T1578

Technique with 5 sub-techniques.View on attack.mitre.org

About this technique

An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots.

Permissions gained from the modification of infrastructure components may bypass restrictions that prevent access to existing infrastructure. Modifying infrastructure components may also allow an adversary to evade detection and remove evidence of their presence.

Detection rules4

Rules on DetectionCode tagged with T1578 or one of its sub-techniques.

Sigma2

Splunk2

RuleTypeRiskData sourceTechnique
Cloud Compute Instance Created With Previously Unseen Instance TypeAnomalyNULLAWS CloudTrailT1578.002
Cloud Security Groups Modifications by UserAnomalyNULLAWS CloudTrailT1578.005

Sub-techniques5

IDNameExamples
T1578.001Create Snapshot1
T1578.002Create Cloud Instance3
T1578.003Delete Cloud Instance2
T1578.004Revert Cloud Instance0
T1578.005Modify Cloud Compute Configurations0

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References1

  1. Mandiant M-Trends 2020 Open source
    Mandiant. (2020, February). M-Trends 2020. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.