kevmap

TechniquesT1546 › AN0027

AN0027 Analytic 0027

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitors cloud function creation triggered by specific audit log events (e.g., IAM changes, object creation), followed by anomalous behavior from new service accounts.</p>
Detects
T1546 Event Triggered Execution
Part of
DET0010 Behavioral Detection of Event Triggered Execution Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailCreateFunctionDC0069 Cloud Service Modification
AWS:CloudTrailInvokeFunctionDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TriggerEventTypeSpecific cloud event (e.g., PutObject, CreateRole) that causes function invocation
ServiceAccountRoleExpected permissions for roles used in function execution