Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0337 — Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance
DET0337

Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0953 Analytic 0953
IaaS

Defenders can detect suspicious reversion of cloud compute instances by monitoring for unusual snapshot restores, rollback actions, or ephemeral storage resets that occur outside expected administrative workflows. From a defender’s perspective, relevant detection chains include: a snapshot restore triggered by a new or rarely used account, a sequence of snapshot creation immediately followed by a restore and instance start, or rollbacks performed from anomalous geographic or network locations. These patterns may indicate attempts to remove forensic evidence or re-establish a clean execution state for persistence.

AWS:CloudTrail RevertSnapshot AWS:CloudTrail StartInstances AWS:CloudTrail StopInstances
[UserContext] Identity of the user or service account performing rollback actions; tuned to exclude automation or approved workflows.
[TimeWindow] Threshold for correlating snapshot creation followed by reversion within minutes; tuned to environment activity norms.
[GeoLocation] Region or source IP where the revert request originated; tuned to align with enterprise cloud geography.
[ChangeTags] Use of administrative tags or headers to distinguish legitimate restores from malicious activity.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0337
STIX ID
x-mitre-detection-strategy--f5ee584b-bbbd-481a-af63-c49166b8b1a8
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.