Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0449 — Detection Strategy for Modify Cloud Compute Infrastructure: Create Cloud Instance
DET0449

Detection Strategy for Modify Cloud Compute Infrastructure: Create Cloud Instance

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1242 Analytic 1242
IaaS

Detection focuses on abnormal or unauthorized cloud instance creation events. From a defender’s perspective, suspicious behavior includes VM/instance creation by rarely used or newly created accounts, creation events from unusual geolocations, or rapid sequences of snapshot creation followed by instance creation and mounting. Unexpected network or IAM policy changes applied to new instances can indicate adversarial use rather than legitimate provisioning.

AWS:CloudTrail RunInstances AWS:CloudTrail DescribeInstances azure:activity MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE
[UserContext] IAM user, service account, or role creating the instance. Tuned to allowlist known automation services.
[GeoLocation] Region or source IP where the creation request originates. Helps detect cross-region or unusual location abuse.
[RateThreshold] Number of instances created per user or account in a time window. Tuned for environments with elastic scaling.
[TaggingPolicy] Expected tags (e.g., owner, purpose, cost center) for new instances. Deviations may indicate adversarial creation.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0449
STIX ID
x-mitre-detection-strategy--bd0b0c98-3c22-4bf8-830b-2640b39eacea
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.