{"id":"T1526","name":"Cloud Service Discovery","url":"https://attack.mitre.org/techniques/T1526","tactics":["discovery"],"platforms":["IaaS","Identity Provider","Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0402","stix_id":"x-mitre-detection-strategy--a9351ea0-8379-47cd-a5c5-c5cf424249ef","name":"Detection Strategy for Cloud Service Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0402","analytics":[{"id":"AN1127","stix_id":"x-mitre-analytic--fe8c1ef5-59ed-40c3-b7f6-eb560555ee22","name":"Analytic 1127","description":"Unusual enumeration of services and resources through cloud APIs such as AWS CLI `describe-*`, Azure Resource Manager queries, or GCP project listings. Defender perspective includes anomalous API calls, unexpected volume of service enumeration, and correlation of discovery with recently compromised sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0402#AN1127","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"DescribeInstances, DescribeServices, ListFunctions: High frequency enumeration calls or unusual user agents performing discovery","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"AssumeRole: Discovery actions tied to assumed identities outside of normal context","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"EnumerationRateThreshold","description":"Rate of API calls used to enumerate services; tuned to reduce noise from automated inventory tools."},{"field":"UserAgentFilter","description":"Expected user agents for cloud management tools; deviations may indicate adversarial tools."}],"live":true,"detection_strategies":["DET0402"],"techniques":["T1526"]},{"id":"AN1128","stix_id":"x-mitre-analytic--e2dd9fee-91b7-4e32-8031-69ed4d7b927c","name":"Analytic 1128","description":"Enumeration of directories, applications, or service principals through APIs such as Microsoft Graph or Okta API. Defender perspective includes unexpected listing of users, roles, applications, and abnormal access to identity management endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0402#AN1128","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:audit","channel":"ListApplications, ListServicePrincipals: Large-scale queries against identity or application objects","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"azure-audit"},{"name":"azure:signinlogs","channel":"InteractiveUserLogin: Discovery behavior linked to privileged logins from atypical IP ranges","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"QueryVolumeThreshold","description":"Threshold for number of object enumeration calls before triggering detection."},{"field":"PrivilegedRoleList","description":"High-value identity roles (Global Admin, Application Admin) for targeted discovery monitoring."}],"live":true,"detection_strategies":["DET0402"],"techniques":["T1526"]},{"id":"AN1129","stix_id":"x-mitre-analytic--19b6de3a-032f-4dc8-aa72-7cd952dfed59","name":"Analytic 1129","description":"Discovery of SaaS services connected to productivity platforms (e.g., Microsoft 365, Google Workspace). Defender perspective includes unexpected enumeration of enabled services, API integrations, or OAuth applications tied to user accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0402#AN1129","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Get-MsolServicePrincipal, ListAppRoles: Service discovery operations executed by accounts not normally performing administrative tasks","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"m365-unified"},{"name":"m365:signinlogs","channel":"UserLogin: Discovery operations shortly after account logins from new geolocations","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"m365-signinlogs"}],"mutable_elements":[{"field":"MonitoredAppIntegrations","description":"Specific Office Suite applications or plugins that may be enumerated or targeted."},{"field":"GeoLocationDeviation","description":"Geographic deviation threshold for discovery actions linked to recent logins."}],"live":true,"detection_strategies":["DET0402"],"techniques":["T1526"]},{"id":"AN1130","stix_id":"x-mitre-analytic--a0730d9f-0a05-4153-8c6a-6f04f9f7346c","name":"Analytic 1130","description":"Discovery of connected SaaS applications, APIs, or configurations within platforms like Salesforce, Slack, or Zoom. Defender perspective includes enumeration of available integrations, abnormal querying of service metadata, and follow-on attempts to exploit or persist via discovered services.","url":"https://attack.mitre.org/detectionstrategies/DET0402#AN1130","platforms":["SaaS"],"log_source_references":[{"name":"saas:adminapi","channel":"ListIntegrations, ListServices: Repeated service discovery requests from accounts without administrative responsibilities","data_component":"DC0083","data_component_name":"Cloud Service Enumeration","log_source_slug":"saas-adminapi"},{"name":"saas:auth","channel":"Login, TokenGranted: Discovery actions tied to anomalous login sessions or tokens","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"saas-auth"}],"mutable_elements":[{"field":"IntegrationDiscoveryThreshold","description":"Number of SaaS integrations enumerated before triggering detection."},{"field":"ServiceAccountScope","description":"Expected permissions for service accounts to distinguish benign from malicious discovery."}],"live":true,"detection_strategies":["DET0402"],"techniques":["T1526"]}],"live":true,"version":"1.0","techniques":["T1526"]}],"sigma_rules":[{"id":"35b781cc-1a08-4a5a-80af-42fd7c315c6b","title":"Discovery Using AzureHound","author":"Janantha Marasinghe","status":"test","level":"high","date":"2022-11-27","modified":null,"description":"Detects AzureHound (A BloodHound data collector for Microsoft Azure) activity via the default User-Agent that is used during its operation after successful authentication.","references":["https://github.com/BloodHoundAD/AzureHound"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.discovery","attack.t1087.004","attack.t1526"],"path":"rules/cloud/azure/signin_logs/azure_ad_azurehound_discovery.yml","techniques":["T1087.004","T1526"],"cves":[]},{"id":"38646daa-e78f-4ace-9de0-55547b2d30da","title":"PUA - Seatbelt Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-10-18","modified":"2023-02-04","description":"Detects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters","references":["https://github.com/GhostPack/Seatbelt","https://www.bluetangle.dev/2022/08/fastening-seatbelt-on-threat-hunting.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1526","attack.t1087","attack.t1083"],"path":"rules/windows/process_creation/proc_creation_win_pua_seatbelt.yml","techniques":["T1526","T1087","T1083"],"cves":[]},{"id":"f8ed0e8f-7438-4b79-85eb-f358ef2fbebd","title":"Github Self Hosted Runner Changes Detected","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"low","date":"2023-01-27","modified":null,"description":"A self-hosted runner is a system that you deploy and manage to execute jobs from GitHub Actions on GitHub.com.\nThis rule detects changes to self-hosted runners configurations in the environment. The self-hosted runner configuration changes once detected,\nit should be validated from GitHub UI because the log entry may not provide full context.\n","references":["https://docs.github.com/en/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners","https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization#search-based-on-operation"],"logsource":{"product":"github","service":"audit"},"tags":["attack.impact","attack.discovery","attack.collection","attack.persistence","attack.privilege-escalation","attack.initial-access","attack.stealth","attack.t1526","attack.t1213.003","attack.t1078.004"],"path":"rules/application/github/audit/github_self_hosted_runner_changes_detected.yml","techniques":["T1526","T1213.003","T1078.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}