Cloud Administration Command T1651
Tactic: Execution
Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.
Events covered
10 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Defender-DeviceFileEvents | any | File activity |
| Defender-DeviceFileEvents | FileCreated | File created |
| Defender-DeviceNetworkEvents | ConnectionSuccess | Connection succeeded |
| Defender-DeviceNetworkEvents | ConnectionFailed | Connection failed |
| Defender-DeviceNetworkEvents | ConnectionRequest | Connection request |
| Defender-DeviceNetworkEvents | ConnectionAttempt | Connection attempt |
| Defender-IdentityInfo | any | Identity information |
| ESF | exec | Process Execution |
Authoring guide
These 27 rules share fields, values, and exclusions.
Fields filtered most (65 distinct)
These fields appear most often in rule filters.
Top indicator values (219 distinct)
These values appear most often in rule predicates.
Exclusions (57 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Elastic 16 rules
- AWS EC2 LOLBin Execution via SSM SendCommand
- AWS SSM `SendCommand` Execution by Rare User
- AWS SSM `SendCommand` with Run Shell Command Parameters
- AWS SSM Command Document Created by Rare User
- AWS SSM Session Manager Child Process Execution
- Azure Compute VM Command Executed
- Azure Run Command Correlated with Process Execution
- Azure Run Command Script Child Process
- Azure Virtual Machine Configuration Modified
- Azure VM Extension CRUD Operation with Unusual Source ASN
- Azure VM Extension Deployment by User
- Azure VM Managed Run Command Created or Updated with Unusual Principal
- First Time AWS CloudFormation Stack Creation
- GCP Pub/Sub Topic Creation
- Suspicious Child Process via Azure VM CustomScript Extension
- Unusual Azure VM Extension Detected
Kusto 9 rules
- AWSCloudTrail - Suspicious command sent to EC2
- Detect Custom Script or Run Command deployment by risky user
- Detect entra token request via specific BOF (IOC based)
- Detect executable drops via Azure custom script extension
- Detect first time Azure Custom Script or Run Command deployment
- Detect non-admin requesting token for admin applications
- Detect process drops via Azure Custom Script Extension performing lateral movement
- Detect suspicious foci token logins
- Detect suspicious foci token logins V2