Technique with 5 sub-techniques.View on attack.mitre.org
An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots.
Permissions gained from the modification of infrastructure components may bypass restrictions that prevent access to existing infrastructure. Modifying infrastructure components may also allow an adversary to evade detection and remove evidence of their presence.
Rules on DetectionCode tagged with T1578 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Azure Active Directory Hybrid Health AD FS New Server | medium | azure / NULL | T1578 |
| Azure Active Directory Hybrid Health AD FS Service Delete | medium | azure / NULL | T1578.003 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cloud Compute Instance Created With Previously Unseen Instance Type | Anomaly | NULL | AWS CloudTrail | T1578.002 |
| Cloud Security Groups Modifications by User | Anomaly | NULL | AWS CloudTrail | T1578.005 |
None recorded.
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.