// MITRE ATT&CK

T1496.004 · Cloud Service Hijacking

🎯 Impact SaaS Sub-technique

Sub-technique of T1496 · Resource Hijacking.

Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability. For example, adversaries may leverage email and messaging services, such as AWS Simple Email Service (SES), AWS Simple Notification Ser...

How to detect & mitigate it

Detecting Cloud Service Hijacking starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.