Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0308 — Detection Strategy for Modify Cloud Compute Infrastructure
DET0308

Detection Strategy for Modify Cloud Compute Infrastructure

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0861 Analytic 0861
IaaS

Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious.

AWS:CloudTrail RunInstances AWS:CloudTrail TerminateInstances AWS:CloudTrail ModifyVolume AWS:CloudTrail DeleteVolume, ModifyVolume AWS:CloudTrail CreateVolume AWS:CloudTrail CreateSnapshot AWS:CloudTrail DeleteSnapshot AWS:CloudTrail ModifySnapshotAttribute AWS:CloudWatch unexpected IAM user or role assuming privileges for instance/snapshot operations
[ChangeWindow] Approved maintenance or deployment windows. Helps reduce false positives by distinguishing scheduled activity.
[UserContext] IAM user, role, or service account performing the operation. Tunable to allowlist known automation services.
[RateThreshold] Number of infrastructure changes (e.g., snapshot creations) in a defined period. Adjusted based on workload scale.
[GeoLocation] Region or source IP where changes originate. Useful for tuning alerts to account for multi-region deployments.

Detected Techniques

1

Details

MITRE ID
DET0308
STIX ID
x-mitre-detection-strategy--af0d25b2-1912-4821-85db-305abe318535
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.