{"id":"T1651","name":"Cloud Administration Command","url":"https://attack.mitre.org/techniques/T1651","tactics":["execution"],"platforms":["IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0545","stix_id":"x-mitre-detection-strategy--fda20a62-ad83-4d45-8a65-84883b07707b","name":"Detection Strategy for Cloud Administration Command","url":"https://attack.mitre.org/detectionstrategies/DET0545","analytics":[{"id":"AN1502","stix_id":"x-mitre-analytic--d8d5a1c0-9ba1-4735-af42-3d5b9d7a6603","name":"Analytic 1502","description":"Monitor for suspicious use of cloud-native administrative command services (e.g., AWS Systems Manager Run Command, Azure RunCommand, GCP OS Config) to execute code inside VMs. Detect anomalies such as commands/scripts executed by unexpected users, execution outside of maintenance windows, or commands initiated by service accounts not normally tied to administration. Correlate cloud control-plane activity logs with host-level execution (process creation, script execution) to validate if commands materialized inside the guest OS.","url":"https://attack.mitre.org/detectionstrategies/DET0545#AN1502","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"SendCommand, StartSession, ExecuteCommand: Unexpected AWS Systems Manager command execution targeting EC2 instances","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"aws-cloudtrail"},{"name":"azure:activity","channel":"Microsoft.Compute/virtualMachines/runCommand/action: Abnormal initiation of Azure RunCommand jobs or PowerShell/Bash payloads","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"azure-activity"},{"name":"azure:vmguest","channel":"Unexpected execution of cloud agent processes (e.g., WindowsAzureGuestAgent.exe, ssm-agent) followed by arbitrary script or binary execution","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"azure-vmguest"}],"mutable_elements":[{"field":"UserContext","description":"Differentiate between known admin/service accounts and non-administrative users triggering RunCommand or SSM."},{"field":"TimeWindow","description":"Correlate cloud control-plane API calls with host-side execution events within a bounded timeframe (e.g., 5 minutes)."},{"field":"AllowedScripts","description":"Whitelist approved scripts or automation invoked via RunCommand to reduce false positives."}],"live":true,"detection_strategies":["DET0545"],"techniques":["T1651"]}],"live":true,"version":"1.0","techniques":["T1651"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}