For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cloud infrastructure discovery across multiple regions

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Infrastructure Discovery (T1580)

Severity

Informational

Description

Discovery API calls were executed across multiple AWS regions.

Attacker's Goals

  • Discover resources across regions to understand the cloud deployment footprint.

  • Target regions or services that may have weaker controls, lower visibility, or misconfiguration for potential exploitation.

  • Build a complete view of infrastructure for lateral movement or privilege escalation.

Investigative actions

  • Identify which services and regions were targeted.

  • Analyze the identity performing the discovery.

  • Correlate with other discovery or suspicious activities.

Variations

Cloud infrastructure discovery across multiple AWS services within a single region

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Infrastructure Discovery (T1580)

Severity

Informational

Description

Discovery API calls were executed across multiple AWS regions.

Attacker's Goals

  • Discover resources across regions to understand the cloud deployment footprint.

  • Target regions or services that may have weaker controls, lower visibility, or misconfiguration for potential exploitation.

  • Build a complete view of infrastructure for lateral movement or privilege escalation.

Investigative actions

  • Identify which services and regions were targeted.

  • Analyze the identity performing the discovery.

  • Correlate with other discovery or suspicious activities.

Cloud infrastructure discovery across multiple AWS services and regions

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Infrastructure Discovery (T1580)

Severity

Low

Description

Discovery API calls were executed across multiple AWS regions.

Attacker's Goals

  • Discover resources across regions to understand the cloud deployment footprint.

  • Target regions or services that may have weaker controls, lower visibility, or misconfiguration for potential exploitation.

  • Build a complete view of infrastructure for lateral movement or privilege escalation.

Investigative actions

  • Identify which services and regions were targeted.

  • Analyze the identity performing the discovery.

  • Correlate with other discovery or suspicious activities.

Was this helpful?