Unusual cloud Instance Metadata Service (IMDS) access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detection Modules
Cloud
Detector Tags
Kubernetes - AGENT, Kubernetes Credentials Theft Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Unsecured Credentials: Cloud Instance Metadata API (T1552.005)
Severity
Informational
Description
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment.
Attacker's Goals
Extract sensitive cloud compute tokens to access restricted cloud resources.
Investigative actions
Determine whether a web service was involved and if it was exploited to execute this technique.
Identify any additional commands that were executed.
Review the permissions assigned to the target machine to identify which resources may be affected.
Examine related compute activity in the cloud audit logs.
Variations
Was this helpful?
