// MITRE ATT&CK

T1578.002 · Create Cloud Instance

🎯 Defense Impairment IaaS Sub-technique

Sub-technique of T1578 · Modify Cloud Compute Infrastructure.

An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new instance may allow an adversary to bypass firewall rules and permissions that exist on instances currently residing within an account. An adversary may [Crea...

How to detect & mitigate it

Detecting Create Cloud Instance starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.