Cloud Service Discovery T1526

Tactic: Discovery

An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs.

Events covered

2 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 48 rules share fields, values, and exclusions.

Fields filtered most (105 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
data_stream.dataset10eq 9, in 1aws.cloudtrail, azure.aadgraphactivitylogs, azure.signinlogs, azure.activitylogs, azure.auditlogs
sourcetype7eq 7aws:cloudwatchlogs:eks, azure:monitor:aad, aws:cloudtrail, google:gcp:pubsub:message, kube:objects:events
EventType6eq 3, in 3, ne 1ListFoundationModels, assumerolewithwebidentity, attachrolepolicy, converse, conversestream
Provider_Name5eq 3, in 2bedrock.amazonaws.com, cloudtrail.amazonaws.com, dynamodb.amazonaws.com, cloudfront.amazonaws.com, s3.amazonaws.com
aws::userIdentity.type5eq 3, ne 2awsservice, AWSAccount, IAMUser, assumedrole
aws::errorCode4eq 3, is_null 1AccessDenied, VpceAccessDenied
Message3eq 2, contains 1UserSignIn, unauthorized access attempt
aws::eventName3eq 1, in 1, starts_with 1ModifyDocumentPermission, PutConfigurationRecorder, PutDeliveryChannel, StartConfigurationRecorder, describe
aws::userAgent3eq 1, is_not_null 1, regex_match 1(azure|sharp|blood)(hound)/.*, mozilla/5.0 (windows nt 10.0; win64; x64)...
category3eq 2, in 1microsoftgraphactivitylogs, kube-audit, noninteractiveusersigninlogs
event.outcome3eq 3success
user3ne 2, starts_with 1awsserviceroleforconfig, system:serviceaccount:, unknown
ClientIp2is_not_null 2
aws::sessionCredentialFromConsole2is_null 2
aws::userIdentity.arn2is_not_null 2

Top indicator values (287 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
data_stream.dataseteq
aws.cloudtrail
4169
data_stream.dataseteq
azure.aadgraphactivitylogs
46
data_stream.dataseteq
azure.signinlogs
236
event.outcomeeq
success
3369
EventTypein
describeinstances
22
EventTypein
getcalleridentity
22
EventTypein
listbuckets
22
EventTypein
listfunctions
22
EventTypein
listkeys
22
EventTypein
listroles
22
EventTypein
listusers
22
Messageeq
UserSignIn
26
Provider_Namein
cloudtrail.amazonaws.com
22
Provider_Namein
dynamodb.amazonaws.com
22
Provider_Namein
ec2.amazonaws.com
22
Provider_Namein
iam.amazonaws.com
22
Provider_Namein
kms.amazonaws.com
22
Provider_Namein
lambda.amazonaws.com
22
Provider_Namein
rds.amazonaws.com
22
Provider_Namein
s3.amazonaws.com
22
Provider_Namein
sts.amazonaws.com
22
aws::errorCodeeq
AccessDenied
23
aws::userIdentity.typene
awsservice
26
sourcetypeeq
aws:cloudwatchlogs:eks
22
sourcetypeeq
azure:monitor:aad
247
user.usernameeq
system:anonymous
25
Activeeq
true
170
AlertSeveritycontains
high
1
AlertSeveritycontains
medium
1
AppIdeq
51f81489-12ee-4a9e-aaae-a2591f45987d
1

Exclusions (34 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
eventCategoryne
NetworkActivity
3
eventTypene
AwsVpceEvent
3
ClientIpcidr_match
10.0.0.0/8
1
ClientIpcidr_match
127.0.0.0/8
1
ClientIpcidr_match
169.254.0.0/16
1
ClientIpcidr_match
172.16.0.0/12
1
ClientIpcidr_match
192.168.0.0/16
1
ClientIpstarts_with
127.
1
ClientIpstarts_with
::
1
ClientIpstarts_with
fe80
1
GCPUserUPNcontains
gserviceaccount.com
1
Labelscontains
synced
1
TI_ipEntitycidr_match
10.0.0.0/8
1
TI_ipEntitycidr_match
127.0.0.0/8
1
TI_ipEntitycidr_match
169.254.0.0/16
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 19 rules

Splunk 8 rules

Kusto 9 rules

Panther 9 rules