Umbra Wiki technique technique/T1578.002
Back to wiki

T1578.002 — Create Cloud Instance

provenance: imported · ATT&CK: T1578.002

T1578.002: Create Cloud Instance

MITRE ATT&CK® Enterprise technique

Tactics Defense Impairment
Platforms IaaS
Permissions required
Version 2.0
Parent technique T1578

Description

An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new instance may allow an adversary to bypass firewall rules and permissions that exist on instances currently residing within an account. An adversary may Create Snapshot of one or more volumes in an account, create a new instance, mount the snapshots, and then apply a less restrictive security policy to collect Data from Local System or for Remote Data Staging.(Citation: Mandiant M-Trends 2020)

Creating a new instance may also allow an adversary to carry out malicious activity within an environment without affecting the execution of current running instances.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1578/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/