Cloud Service Dashboard T1538
Tactic: Discovery
An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features. For example, the GCP Command Center can be used to view all assets, review findings of potential security risks, and run additional queries, such as finding public IP addresses and open ports.
Authoring guide
These 4 rules share fields, values, and exclusions.
Fields filtered most (18 distinct)
These fields appear most often in rule filters.
Top indicator values (30 distinct)
These values appear most often in rule predicates.
Exclusions (3 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.