kevmap

TechniquesT1049 › AN0908

AN0908 Analytic 0908

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI).</p>
Detects
T1049 System Network Connections Discovery
Part of
DET0320 Detection of System Network Connections Discovery Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailDescribe* or List* API callsDC0021 OS API Execution
azure:activitynetworkInsightsLogsDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ServicePrincipalAllowlistAllow certain automation roles to perform discovery during provisioning.
BurstQueryThresholdUnusual number of Describe* or List* network API calls in a short timeframe.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-41328Fortinet FortiOSMapped