kevmap

TechniquesT1535 › AN0690

AN0690 Analytic 0690

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).</p>
Detects
T1535 Unused/Unsupported Cloud Regions
Part of
DET0247 Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailRunInstancesDC0080 Instance Start
AWS:CloudTrailCreateBucketDC0024 Cloud Storage Creation
CloudTrail:GetCallerIdentityGetCallerIdentityDC0013 User Account Metadata
AWS:VPCFlowLogsHigh outbound traffic from new region resourceDC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UnusedRegionListList of regions historically unused by the organization (can vary per tenant/project)
TimeWindowTime interval for correlating activity following account access
AllowedServiceListWhitelist of services allowed in secondary/DR regions
OutboundTrafficThresholdVolume threshold to flag suspicious outbound activity