Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0545 — Detection Strategy for Cloud Administration Command
DET0545

Detection Strategy for Cloud Administration Command

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1502 Analytic 1502
IaaS

Monitor for suspicious use of cloud-native administrative command services (e.g., AWS Systems Manager Run Command, Azure RunCommand, GCP OS Config) to execute code inside VMs. Detect anomalies such as commands/scripts executed by unexpected users, execution outside of maintenance windows, or commands initiated by service accounts not normally tied to administration. Correlate cloud control-plane activity logs with host-level execution (process creation, script execution) to validate if commands materialized inside the guest OS.

AWS:CloudTrail SendCommand, StartSession, ExecuteCommand: Unexpected AWS Systems Manager command execution targeting EC2 instances azure:activity Microsoft.Compute/virtualMachines/runCommand/action: Abnormal initiation of Azure RunCommand jobs or PowerShell/Bash payloads azure:vmguest Unexpected execution of cloud agent processes (e.g., WindowsAzureGuestAgent.exe, ssm-agent) followed by arbitrary script or binary execution
[UserContext] Differentiate between known admin/service accounts and non-administrative users triggering RunCommand or SSM.
[TimeWindow] Correlate cloud control-plane API calls with host-side execution events within a bounded timeframe (e.g., 5 minutes).
[AllowedScripts] Whitelist approved scripts or automation invoked via RunCommand to reduce false positives.

Detected Techniques

1

Details

MITRE ID
DET0545
STIX ID
x-mitre-detection-strategy--fda20a62-ad83-4d45-8a65-84883b07707b
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.