Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0247 — Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)
DET0247

Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0690 Analytic 0690
IaaS

Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).

AWS:CloudTrail RunInstances AWS:CloudTrail CreateBucket CloudTrail:GetCallerIdentity GetCallerIdentity AWS:VPCFlowLogs High outbound traffic from new region resource
[UnusedRegionList] List of regions historically unused by the organization (can vary per tenant/project)
[TimeWindow] Time interval for correlating activity following account access
[AllowedServiceList] Whitelist of services allowed in secondary/DR regions
[OutboundTrafficThreshold] Volume threshold to flag suspicious outbound activity

Detected Techniques

1

Details

MITRE ID
DET0247
STIX ID
x-mitre-detection-strategy--ec3e5f66-a2b8-48ae-9adf-eb4f5014ba70
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.