kevmap

TechniquesT1528 › AN1424

AN1424 Analytic 1424

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Token retrieval from instance metadata endpoints such as AWS IMDS or Azure IMDS, followed by API usage using the obtained token from non-standard applications.</p>
Detects
T1528 Steal Application Access Token
Part of
DET0515 Detection Strategy for T1528 - Steal Application Access Token

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailGetInstanceIdentityDocument or IMDSv2 token requestsDC0083 Cloud Service Enumeration
AWS:CloudTrailUse of temporary credentials issued from IMDS accessDC0069 Cloud Service Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserAgentMay need tuning for known automation tools versus unexpected curl usage
TimeWindowCorrelate retrieval and use of token within expected timeout window

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2024-38475Apache HTTP ServerMapped