Unused/Unsupported Cloud Regions T1535
Tactic: Stealth
Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accounts used to manage cloud infrastructure.
Authoring guide
These 10 rules share fields, values, and exclusions.
Fields filtered most (16 distinct)
These fields appear most often in rule filters.
Top indicator values (20 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Cloud
Splunk 5 rules
- AWS Successful Console Authentication From Multiple IPs
- Cloud Compute Instance Created In Previously Unused Region
- Detect AWS Console Login by User from New City
- Detect AWS Console Login by User from New Country
- Detect AWS Console Login by User from New Region