Cloud Service Discovery T1526
Tactic: Discovery
An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Defender-IdentityInfo | any | Identity information |
Authoring guide
These 48 rules share fields, values, and exclusions.
Fields filtered most (105 distinct)
These fields appear most often in rule filters.
Top indicator values (287 distinct)
These values appear most often in rule predicates.
Exclusions (34 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
Elastic 19 rules
- AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key
- AWS Discovery API Calls from VPN ASN for the First Time by Identity
- AWS Discovery API Calls via CLI from a Single Resource
- AWS Lateral Movement from Kubernetes SA via AssumeRoleWithWebIdentity
- AWS S3 Rapid Bucket Posture API Calls from a Single Principal
- AWS Service Quotas Multi-Region GetServiceQuota Requests
- Azure AD Graph Access with Suspicious User-Agent
- Azure AD Graph High 4xx Error Ratio from User
- Azure AD Graph Potential Enumeration (ROADrecon)
- Entra ID OAuth Device Code Sign-in to Azure AD Graph Enumeration
- Entra ID Sign-in BloodHound Suite User-Agent Detected
- Entra ID Sign-in TeamFiltration User-Agent Detected
- Microsoft Graph Multi-Category Reconnaissance Burst
- Rare AWS Error Code
- Rare Azure Activity Logs Event Failures
- Rare GCP Audit Failure Event Code
- Spike in AWS Error Messages
- Spike in Azure Activity Logs Failed Messages
- Spike in GCP Audit Failed Messages
Splunk 8 rules
- Amazon EKS Kubernetes cluster scan detection
- Amazon EKS Kubernetes Pod scan detection
- AWS Excessive Security Scanning
- Azure AD AzureHound UserAgent Detected
- Azure AD Service Principal Enumeration
- GCP Kubernetes cluster pod scan detection
- Kubernetes Scanner Image Pulling
- Kubernetes Suspicious Image Pulling
Kusto 9 rules
- AWSCloudTrail - SSM document is publicly exposed
- Dataverse - Honeypot instance activity
- Dataverse - Suspicious use of Web API
- Dataverse - TI map IP to DataverseActivity
- Netskope - New Risky App Access vs 7-Day Baseline
- SAP BTP - Failed access attempts across multiple BAS subaccounts
- Snowflake - Possible discovery activity
- SOCRadar Unsynced Closed Incident
- Suspicious VM Instance Creation Activity Detected