Serverless Execution T1648
Tactic: Execution
Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments. Many cloud providers offer a variety of serverless resources, including compute engines, application integration services, and web servers.
Authoring guide
These 17 rules share fields, values, and exclusions.
Fields filtered most (23 distinct)
These fields appear most often in rule filters.
Top indicator values (31 distinct)
These values appear most often in rule predicates.
Exclusions (6 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Cloud
Elastic 16 rules
- AWS Lambda Event Source Mapping Creation
- AWS Lambda Function Created or Updated
- AWS Lambda Function Invoked by an Unusual Principal
- AWS Lambda Function Invoked Cross-Account
- AWS Lambda Function Invoked from an Unusual Source ASN
- AWS Lambda Layer Added to Existing Function
- AWS Lambda Layer Shared Externally
- Azure Automation Runbook Created or Modified
- First Occurrence GitHub Event for a Personal Access Token (PAT)
- First Occurrence of GitHub Repo Interaction From a New IP
- First Occurrence of GitHub User Interaction with Private Repo
- First Occurrence of Private Repo Event from Specific GitHub Personal Access Token (PAT)
- First Time AWS CloudFormation Stack Creation
- GitHub App Deleted
- GitHub Repo Created
- High Number of Cloned GitHub Repos From PAT