Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0402 — Detection Strategy for Cloud Service Discovery
DET0402

Detection Strategy for Cloud Service Discovery

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1127 Analytic 1127
IaaS

Unusual enumeration of services and resources through cloud APIs such as AWS CLI `describe-*`, Azure Resource Manager queries, or GCP project listings. Defender perspective includes anomalous API calls, unexpected volume of service enumeration, and correlation of discovery with recently compromised sessions.

AWS:CloudTrail DescribeInstances, DescribeServices, ListFunctions: High frequency enumeration calls or unusual user agents performing discovery AWS:CloudTrail AssumeRole: Discovery actions tied to assumed identities outside of normal context
[EnumerationRateThreshold] Rate of API calls used to enumerate services; tuned to reduce noise from automated inventory tools.
[UserAgentFilter] Expected user agents for cloud management tools; deviations may indicate adversarial tools.
AN1128 Analytic 1128
Identity Provider

Enumeration of directories, applications, or service principals through APIs such as Microsoft Graph or Okta API. Defender perspective includes unexpected listing of users, roles, applications, and abnormal access to identity management endpoints.

azure:audit ListApplications, ListServicePrincipals: Large-scale queries against identity or application objects azure:signinlogs InteractiveUserLogin: Discovery behavior linked to privileged logins from atypical IP ranges
[QueryVolumeThreshold] Threshold for number of object enumeration calls before triggering detection.
[PrivilegedRoleList] High-value identity roles (Global Admin, Application Admin) for targeted discovery monitoring.
AN1129 Analytic 1129
Office Suite

Discovery of SaaS services connected to productivity platforms (e.g., Microsoft 365, Google Workspace). Defender perspective includes unexpected enumeration of enabled services, API integrations, or OAuth applications tied to user accounts.

m365:unified Get-MsolServicePrincipal, ListAppRoles: Service discovery operations executed by accounts not normally performing administrative tasks m365:signinlogs UserLogin: Discovery operations shortly after account logins from new geolocations
[MonitoredAppIntegrations] Specific Office Suite applications or plugins that may be enumerated or targeted.
[GeoLocationDeviation] Geographic deviation threshold for discovery actions linked to recent logins.
AN1130 Analytic 1130
SaaS

Discovery of connected SaaS applications, APIs, or configurations within platforms like Salesforce, Slack, or Zoom. Defender perspective includes enumeration of available integrations, abnormal querying of service metadata, and follow-on attempts to exploit or persist via discovered services.

saas:adminapi ListIntegrations, ListServices: Repeated service discovery requests from accounts without administrative responsibilities saas:auth Login, TokenGranted: Discovery actions tied to anomalous login sessions or tokens
[IntegrationDiscoveryThreshold] Number of SaaS integrations enumerated before triggering detection.
[ServiceAccountScope] Expected permissions for service accounts to distinguish benign from malicious discovery.

Detected Techniques

1

Details

MITRE ID
DET0402
STIX ID
x-mitre-detection-strategy--a9351ea0-8379-47cd-a5c5-c5cf424249ef
Analytics
4
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.