{"id":"T1538","name":"Cloud Service Dashboard","url":"https://attack.mitre.org/techniques/T1538","tactics":["discovery"],"platforms":["IaaS","SaaS","Office Suite","Identity Provider"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0291","stix_id":"x-mitre-detection-strategy--e2bf0a76-b5e4-4a23-adbb-024454f5dbdc","name":"Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access","url":"https://attack.mitre.org/detectionstrategies/DET0291","analytics":[{"id":"AN0808","stix_id":"x-mitre-analytic--c8a50f3f-105a-4107-9781-a3d75479e93d","name":"Analytic 0808","description":"Detects web console login events followed by read-only or metadata retrieval activity from GUI sources (e.g., browser session, mobile client) rather than API/CLI sources. Correlates across CloudTrail, IAM identity logs, and user-agent context.","url":"https://attack.mitre.org/detectionstrategies/DET0291#AN0808","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"ConsoleLogin","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"Post-authentication metadata enumeration from GUI session","data_component":"DC0027","data_component_name":"Cloud Storage Metadata","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"UserAgentFilter","description":"Allowlist/denylist of user agents to distinguish browser-based vs. CLI/API sessions"},{"field":"TimeWindow","description":"Maximum time delta between login and suspicious GUI activity"},{"field":"PrivilegedSessionThreshold","description":"Login attempts to dashboard using elevated IAM roles"}],"live":true,"detection_strategies":["DET0291"],"techniques":["T1538"]},{"id":"AN0809","stix_id":"x-mitre-analytic--041c0b93-fda4-478f-b847-d10619db729c","name":"Analytic 0809","description":"Detects successful login to cloud identity portals (e.g., Okta, Azure AD, Google Identity) from atypical geolocations, devices, or user agents immediately followed by dashboard/portal navigation to sensitive pages such as user or app configuration.","url":"https://attack.mitre.org/detectionstrategies/DET0291#AN0809","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Sign-in with unfamiliar location/device + portal navigation","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"},{"name":"saas:okta","channel":"user.session.start","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"saas-okta"},{"name":"saas:okta","channel":"WebUI access to administrator dashboard","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"GeoIPAnomalyThreshold","description":"Threshold for location anomalies per user profile"},{"field":"UserAgentReputation","description":"Unknown browser/device fingerprint list"},{"field":"PrivilegedPageAccess","description":"List of sensitive dashboard views for alerting"}],"live":true,"detection_strategies":["DET0291"],"techniques":["T1538"]},{"id":"AN0810","stix_id":"x-mitre-analytic--a0bfcae2-1936-466d-91b4-f72fcae730b6","name":"Analytic 0810","description":"Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use.","url":"https://attack.mitre.org/detectionstrategies/DET0291#AN0810","platforms":["Office Suite"],"log_source_references":[{"name":"m365:signinlogs","channel":"UserLoginSuccess","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"m365-signinlogs"},{"name":"m365:unified","channel":"ViewAdminReport","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"m365-unified"},{"name":"m365:unified","channel":"Read-only configuration review from GUI","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"AdminRoleList","description":"Roles allowed to access dashboard views"},{"field":"DashboardNavigationSequence","description":"Pageview paths or clickstreams indicating use of GUI admin console"},{"field":"GeoLocationRisk","description":"List of high-risk regions or unexpected geos"}],"live":true,"detection_strategies":["DET0291"],"techniques":["T1538"]},{"id":"AN0811","stix_id":"x-mitre-analytic--d3e3ed48-7402-40df-a6cc-db9b560bcfd1","name":"Analytic 0811","description":"Detects SaaS web login followed by dashboard or web GUI page views from unfamiliar locations, devices, or access patterns. Identifies use of sensitive reporting or configuration consoles accessed from high-risk accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0291#AN0811","platforms":["SaaS"],"log_source_references":[{"name":"saas:zoom","channel":"Zoom Admin Dashboard accessed from unfamiliar IP/device","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"saas-zoom"},{"name":"saas:salesforce","channel":"Login","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-salesforce"},{"name":"saas:box","channel":"User navigated to admin interface","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-box"}],"mutable_elements":[{"field":"SaaSDashboardViewList","description":"List of GUI pages or endpoints considered sensitive"},{"field":"IPReputationThreshold","description":"Reputation score or allowlist of source IPs"},{"field":"LoginBehaviorBaseline","description":"Typical user/device login pairings or login frequency"}],"live":true,"detection_strategies":["DET0291"],"techniques":["T1538"]}],"live":true,"version":"1.0","techniques":["T1538"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}