Cross-source coverage
T1578.005 / ATT&CK
Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
19 rules across 2 sources.
From MITRE ATT&CK 19.2
Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses. These settings may include service quotas, subscription associations, tenant-wide policies, or other configurations that impact available compute. Such modifications may allow adversaries to abuse the victim’s compute resources to achieve their goals, potentially without affecting the execution of running instances and/or revealing their activities to the victim.
For example, cloud providers often limit customer usage of compute resources via quotas. Customers may request adjustments to these quotas to support increased computing needs, though these adjustments may require approval from the cloud provider. Adversaries who compromise a cloud environment may similarly request quota adjustments in order to support their activities, such as enabling additional Resource Hijacking without raising suspicion by using up a victim’s entire quota. Adversaries may also increase allowed resource usage by modifying any tenant-wide policies that limit the sizes of deployed virtual machines.
Adversaries may also modify settings that affect where cloud resources can be deployed, such as enabling Unused/Unsupported Cloud Regions.
- Tactics
- Defense Impairment
- Platforms
- IaaS
- Telemetry
-
AWS:CloudTrail
How MITRE says to detect it DET0492
Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
IaaS Analytic 1356
Defenders should monitor for anomalous or unauthorized changes to cloud compute configurations that alter quotas, tenant-wide policies, subscription associations, or allowed deployment regions. From a defender’s perspective, suspicious behavior chains include a sudden increase in compute quota requests followed by new instance or resource creation, policy modifications that weaken security restrictions, or enabling previously unused/unsupported cloud regions. Correlation across identity, configuration, and subsequent provisioning logs is critical to distinguish legitimate administrative activity from adversarial abuse.
AWS:CloudTrailRequestServiceQuotaIncrease
elastic/detection-rules
18 rules| Detection | Severity | Format |
|---|---|---|
| AWS EC2 Serial Console Access Enabled | High | Elastic TOML |
| AWS Lambda Function Policy Updated to Allow Cross-Account Invocation | High | Elastic TOML |
| AWS Lambda Function Policy Updated to Allow Public Invocation | High | Elastic TOML |
| AWS Lambda Function URL Created with Public Access | High | Elastic TOML |
| AWS EC2 EBS Snapshot Access Removed | Medium | Elastic TOML |
| AWS EC2 Encryption Disabled | Medium | Elastic TOML |
| AWS Lambda Layer Shared Externally | Medium | Elastic TOML |
| AWS RDS DB Instance or Cluster Deletion Protection Disabled | Medium | Elastic TOML |
| GCP Storage Bucket Configuration Modification | Medium | Elastic TOML |
| GCP Virtual Private Cloud Route Deletion | Medium | Elastic TOML |
+ 8 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Cloud Security Groups Modifications by User | Undefined | SPL |