Cross-source coverage

T1578.003 / ATT&CK

Modify Cloud Compute Infrastructure: Delete Cloud Instance

1 rule across 1 source.

From MITRE ATT&CK 19.2

An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence. Deleting an instance or virtual machine can remove valuable forensic artifacts and other evidence of suspicious behavior if the instance is not recoverable.

An adversary may also Create Cloud Instance and later terminate the instance after achieving their objectives.

Platforms
IaaS
Telemetry
AWS:CloudTrailazure:activity

How MITRE says to detect it DET0084

Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance

IaaS Analytic 0234

Defenders can detect suspicious cloud instance deletions by correlating events across authentication, instance lifecycle, and account activity. From a defender’s perspective, behaviors of interest include instances deleted shortly after creation, deletions initiated by new or rarely used accounts, deletions following snapshot creation, and deletions originating from anomalous geolocations or access keys. These may indicate adversarial attempts to destroy forensic evidence or evade detection.

  • AWS:CloudTrail TerminateInstances
  • AWS:CloudTrail DescribeInstances
  • azure:activity MICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE

SigmaHQ/sigma

1 rule
Detection Severity Format
Azure Active Directory Hybrid Health AD FS Service Delete Medium Sigma

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.