Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0147 — Detection Strategy for Cloud Service Hijacking via SaaS Abuse
DET0147

Detection Strategy for Cloud Service Hijacking via SaaS Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0417 Analytic 0417
SaaS

Adversary gains access to cloud-hosted services such as AWS SES, SNS, or OpenAI API, enables or modifies usage policies, and initiates resource-intensive actions (e.g., mass email/SMS or LLM queries), often from unauthorized regions or under anomalous identity conditions.

AWS:CloudTrail PutIdentityPolicy AWS:CloudTrail SendEmail AWS:CloudTrail AssumeRole
[TimeWindow] Define threshold period over which request spikes are measured. E.g., 10 min or 1 hour windows.
[UserContext] Alert only if role/user is outside expected automation identity list.
[RequestVolumeThreshold] Customize the number of emails/SMS or API calls considered anomalous.
[GeoVelocityThreshold] Tune geolocation jump logic (e.g., login from US, then use service in Asia within minutes).
[ModelUsageQuotaSpike] Set maximum allowable deviation from past 7-day average OpenAI/GPT token usage.

Detected Techniques

1

Details

MITRE ID
DET0147
STIX ID
x-mitre-detection-strategy--e769419e-39f6-478d-97b8-cf0672fa635b
Analytics
1
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.