Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0156 — Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs
DET0156

Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0443 Analytic 0443
SaaS

Automated and repetitive triggering of SMS messages through OTP/account verification fields on SaaS platforms, leveraging background messaging APIs such as Twilio, AWS SNS, or Amazon Cognito to generate traffic toward attacker-controlled numbers.

saas:application High-frequency invocation of SMS-related API endpoints from publicly accessible OTP or verification forms (e.g., Twilio: SendMessage, Cognito: AdminCreateUser) with irregular destination patterns. saas:audit Repeated requests to SMS-generating endpoints using anomalous or new user agents, IP ranges, or geographies.
[TimeWindow] Defines the rolling window over which SMS API invocation frequency is measured. Tunable based on average platform traffic.
[SMSFrequencyThreshold] Number of SMS requests per endpoint or per user that should trigger investigation. Should align with business logic and user behavior.
[DestinationCountryCodeFilter] Monitors if requests target known high-risk, revenue-sharing regions. Tunable to reflect SMS tariff rates or abuse history.
[UserAgentAnomalyThreshold] Defines outlier score or list of unknown/automated user agents submitting forms.
[IPGeoVarianceScore] Tracks abnormal geographic spread of traffic sourcing OTP triggers.

Detected Techniques

1

Details

MITRE ID
DET0156
STIX ID
x-mitre-detection-strategy--9c36b7a8-22bb-4420-a8ac-8e46ddef5674
Analytics
1
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.