// MITRE ATT&CK
T1578 · Modify Cloud Compute Infrastructure
🎯 Defense Impairment IaaS
An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots. Permi...
¿Cómo detectarlo y mitigarlo?
La detección de Modify Cloud Compute Infrastructure parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (5)
T1578.001
Create Snapshot T1578.002
Create Cloud Instance T1578.003
Delete Cloud Instance T1578.004
Revert Cloud Instance T1578.005
Modify Cloud Compute Configurations
Create Snapshot T1578.002
Create Cloud Instance T1578.003
Delete Cloud Instance T1578.004
Revert Cloud Instance T1578.005
Modify Cloud Compute Configurations
Técnicas relacionadas
T1687
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1600
Weaken Encryption
Exploitation for Defense Impairment T1556.003
Pluggable Authentication Modules T1578.004
Revert Cloud Instance T1222.002
Linux and Mac Permissions T1666
Modify Cloud Resource Hierarchy T1685.003
Modify or Spoof Tool UI T1685.001
Disable or Modify Windows Event Log T1600
Weaken Encryption
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.