Cloud Service Discovery

T1526

Technique.View on attack.mitre.org

About this technique

An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs.

Adversaries may attempt to discover information about the services enabled throughout the environment. Azure tools and APIs, such as the Microsoft Graph API and Azure Resource Manager API, can enumerate resources and services, including applications, management groups, resources and policy definitions, and their relationships that are accessible by an identity.

For example, Stormspotter is an open source tool for enumerating and constructing a graph for Azure resources and services, and Pacu is an open source AWS exploitation framework that supports several methods for discovering cloud services.

Adversaries may use the information gained to shape follow-on behaviors, such as targeting data or credentials from enumerated services or evading identified defenses through Disable or Modify Tools or Disable or Modify Cloud Log.

Detection rules14

Rules on DetectionCode tagged with T1526.

Sigma3

RuleLevelLog source
Discovery Using AzureHoundhighazure / NULL
PUA - Seatbelt Executionhighwindows / process_creation
Github Self Hosted Runner Changes Detectedlowgithub / NULL

Splunk11

RuleTypeRiskData source
Amazon EKS Kubernetes cluster scan detectionHuntingNULL
Amazon EKS Kubernetes Pod scan detectionHuntingNULL
ASL AWS Excessive Security ScanningAnomalyNULL
AWS Excessive Security ScanningTTPNULLAWS CloudTrail
Azure AD AzureHound UserAgent DetectedTTPNULLAzure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs
Azure AD Service Principal EnumerationTTPNULLAzure Active Directory MicrosoftGraphActivityLogs
GCP Kubernetes cluster pod scan detectionHuntingNULL
GCP Kubernetes cluster scan detectionTTPNULL
Kubernetes Azure scan fingerprintHuntingNULL
Kubernetes Scanner Image PullingTTPNULL
Kubernetes Suspicious Image PullingAnomalyNULLKubernetes Audit

Groups1

Software5

Campaigns0

None recorded.

Procedure examples6

Groups1

Used byProcedure example
GroupStorm-0501

Storm-0501 has discovered the victim environment’s protections to include Azure policies, resource locks, and Azure Storage immutability policies.

Software5

Used byProcedure example
ToolAADInternals

AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations.

ToolPacu

Pacu can enumerate AWS services, such as CloudTrail and CloudWatch.

ToolROADTools

ROADTools can enumerate Azure AD applications and service principals.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search GitHub for Actions runner processes.

ToolTruffleHog

TruffleHog has the ability to scan code repositories and CI/CD platforms.

References4

  1. Azure - Resource Manager API Open source
    Microsoft. (2019, May 20). Azure Resource Manager. Retrieved June 17, 2020.
  2. Azure - Stormspotter Open source
    Microsoft. (2020). Azure Stormspotter GitHub. Retrieved June 17, 2020.
  3. Azure AD Graph API Open source
    Microsoft. (2016, March 26). Operations overview | Graph API concepts. Retrieved June 18, 2020.
  4. GitHub Pacu Open source
    Rhino Security Labs. (2019, August 22). Pacu. Retrieved October 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.