Cloud infrastructure discovery across multiple regions
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Cloud Infrastructure Discovery (T1580)
Severity
Informational
Description
Discovery API calls were executed across multiple AWS regions.
Attacker's Goals
Discover resources across regions to understand the cloud deployment footprint.
Target regions or services that may have weaker controls, lower visibility, or misconfiguration for potential exploitation.
Build a complete view of infrastructure for lateral movement or privilege escalation.
Investigative actions
Identify which services and regions were targeted.
Analyze the identity performing the discovery.
Correlate with other discovery or suspicious activities.
Variations
Was this helpful?
