Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0078 — Behavioral Detection of Malicious Cloud API Scripting
DET0078

Behavioral Detection of Malicious Cloud API Scripting

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0215 Analytic 0215
IaaS

Detects adversarial use of cloud APIs for command execution, resource control, or reconnaissance. Focuses on CLI/SDK/scripting language abuse via stolen credentials or in-browser Cloud Shells. Monitors for anomalous API calls chained with authentication context shifts (e.g., stolen token -> privileged action) and cross-service impacts.

AWS:CloudTrail eventName: RunInstances, CreateUser, PutRolePolicy, InvokeCommand azure:activity operationName: Write, Access Review, RoleAssignment Okta:SystemLog eventType: user.authentication.sso, app.oauth2.token.grant
[TimeWindow] Off-hours API usage or configuration changes are more suspicious outside business context.
[UserAgent] Unexpected SDK usage (e.g., `boto3`, `azcopy`, unknown User-Agent strings).
[CredentialType] High-risk if access token or API key used outside expected geographic/IP behavior.
[APISequence] Unusual or rapid chaining of provisioning, IAM, and execution APIs.
[ConsoleContext] Browser-based Cloud Shell vs local CLI may indicate insider vs external use case.

Detected Techniques

1

Execution (1)

Details

MITRE ID
DET0078
STIX ID
x-mitre-detection-strategy--e7bd0f37-f2cf-4e3c-a9c1-c41f63b67e1c
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.