Allocation of multiple cloud compute resources
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040), Initial Access (TA0001)
ATT&CK Technique
Resource Hijacking (T1496), Valid Accounts (T1078)
Severity
Informational
Description
An identity allocated multiple compute resources.
Attacker's Goals
Leverage cloud compute resources to earn virtual currency.
Investigative actions
Check the identity created resources and its legitimacy.
Look for any unusual behavior originated from the suspected identity, and check if they're compromised, e.g. Access key, service account, etc.
Variations
Was this helpful?
