EXPLORE
← Back to Explore
T1580

Cloud Infrastructure Discovery

An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment. This includes compute service resources such as instances, virtual machines, and snapshots as well as resources of other services including the storage and database services. Cloud providers offer methods such as APIs and commands issued through CLIs to serve information about infrastructure. For example, AWS provides a <code>DescribeInstances</code> API...

IaaS
26
Detections
3
Sources
2
Threat Actors

BY SOURCE

20elastic5splunk_escu1sigma

PROCEDURES (16)

Azure3 detections

Auto-extracted: 3 detections for azure

C22 detections

Auto-extracted: 2 detections for c2

Service2 detections

Auto-extracted: 2 detections for service

Evasion2 detections

Auto-extracted: 2 detections for evasion

Aws2 detections

Auto-extracted: 2 detections for aws

Service1 detections

Auto-extracted: 1 detections for service

C21 detections

Auto-extracted: 1 detections for c2

Lateral1 detections

Auto-extracted: 1 detections for lateral

Service1 detections

Auto-extracted: 1 detections for service

Unusual1 detections

Auto-extracted: 1 detections for unusual

Evasion1 detections

Auto-extracted: 1 detections for evasion

Lateral1 detections

Auto-extracted: 1 detections for lateral

Unusual1 detections

Auto-extracted: 1 detections for unusual

Aws1 detections

Auto-extracted: 1 detections for aws

Cloud1 detections

Auto-extracted: 1 detections for cloud

Cloud Monitoring1 detections

Auto-extracted: 1 detections for cloud monitoring

DETECTIONS (26)