{"id":"T1578.004","name":"Revert Cloud Instance","url":"https://attack.mitre.org/techniques/T1578/004","tactics":["defense-impairment"],"platforms":["IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0337","stix_id":"x-mitre-detection-strategy--f5ee584b-bbbd-481a-af63-c49166b8b1a8","name":"Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance","url":"https://attack.mitre.org/detectionstrategies/DET0337","analytics":[{"id":"AN0953","stix_id":"x-mitre-analytic--4eaeffc2-bdfa-427c-a009-daadee39457d","name":"Analytic 0953","description":"Defenders can detect suspicious reversion of cloud compute instances by monitoring for unusual snapshot restores, rollback actions, or ephemeral storage resets that occur outside expected administrative workflows. From a defender’s perspective, relevant detection chains include: a snapshot restore triggered by a new or rarely used account, a sequence of snapshot creation immediately followed by a restore and instance start, or rollbacks performed from anomalous geographic or network locations. These patterns may indicate attempts to remove forensic evidence or re-establish a clean execution state for persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0337#AN0953","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"RevertSnapshot","data_component":"DC0073","data_component_name":"Instance Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"StartInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"StopInstances","data_component":"DC0089","data_component_name":"Instance Stop","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"UserContext","description":"Identity of the user or service account performing rollback actions; tuned to exclude automation or approved workflows."},{"field":"TimeWindow","description":"Threshold for correlating snapshot creation followed by reversion within minutes; tuned to environment activity norms."},{"field":"GeoLocation","description":"Region or source IP where the revert request originated; tuned to align with enterprise cloud geography."},{"field":"ChangeTags","description":"Use of administrative tags or headers to distinguish legitimate restores from malicious activity."}],"live":true,"detection_strategies":["DET0337"],"techniques":["T1578.004"]}],"live":true,"version":"1.0","techniques":["T1578.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}