Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0001 — Detect Access to Cloud Instance Metadata API (IaaS)
DET0001

Detect Access to Cloud Instance Metadata API (IaaS)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0001 Analytic 0001
IaaS

Detects access attempts to cloud instance metadata endpoints (e.g., 169.254.169.254) from virtual machines or containerized workloads. This includes both direct access and SSRF exploitation patterns.

AWS:VPCFlowLogs Outbound connection to 169.254.169.254 from EC2 workload AWS:CloudTrail GetInstanceIdentityDocument ebpf:syscalls Process within container accesses link-local address 169.254.169.254
[TimeWindow] Adjust temporal window for correlation of access attempts and SSRF triggers
[UserContext] Tune based on expected roles that access metadata APIs (e.g., root, service accounts)
[RequestHeaderMatch] Customize detection for HTTP Host headers indicating SSRF

Detected Techniques

1

Details

MITRE ID
DET0001
STIX ID
x-mitre-detection-strategy--6182825d-f41f-4d87-ac93-937f7894ab1d
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.