Cross-source coverage
T1578.003 / ATT&CK
Modify Cloud Compute Infrastructure: Delete Cloud Instance
1 rule across 1 source.
From MITRE ATT&CK 19.2
An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence. Deleting an instance or virtual machine can remove valuable forensic artifacts and other evidence of suspicious behavior if the instance is not recoverable.
An adversary may also Create Cloud Instance and later terminate the instance after achieving their objectives.
- Tactics
- Defense Impairment
- Platforms
- IaaS
- Telemetry
-
AWS:CloudTrailazure:activity
How MITRE says to detect it DET0084
Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance
IaaS Analytic 0234
Defenders can detect suspicious cloud instance deletions by correlating events across authentication, instance lifecycle, and account activity. From a defender’s perspective, behaviors of interest include instances deleted shortly after creation, deletions initiated by new or rarely used accounts, deletions following snapshot creation, and deletions originating from anomalous geolocations or access keys. These may indicate adversarial attempts to destroy forensic evidence or evade detection.
AWS:CloudTrailTerminateInstancesAWS:CloudTrailDescribeInstancesazure:activityMICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| Azure Active Directory Hybrid Health AD FS Service Delete | Medium | Sigma |