Initial construction of a new instance (ex: instance.insert within GCP Audit Logs)
Initial construction of a new instance (ex: instance.insert within GCP Audit Logs)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
.002 | Create Cloud Instance | ||
Enterprise | T1535 | Unused/Unsupported Cloud Regions | |
Enterprise | T1204 | User Execution | |
.003 | Malicious Image |
Removal of an instance (ex: instance.delete within GCP Audit Logs)
Removal of an instance (ex: instance.delete within GCP Audit Logs)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1485 | Data Destruction | |
Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
.003 | Delete Cloud Instance |
An extracted list of instances within a cloud environment (ex: instance.list within GCP Audit Logs)
An extracted list of instances within a cloud environment (ex: instance.list within GCP Audit Logs)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1580 | Cloud Infrastructure Discovery |
Contextual data about an instance and activity around it such as name, type, or status
Contextual data about an instance and activity around it such as name, type, or status
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1580 | Cloud Infrastructure Discovery | |
Enterprise | T1082 | System Information Discovery | |
Enterprise | T1614 | System Location Discovery |
Changes made to an instance, including its settings and/or control data (ex: instance.addResourcePolicies or instances.setMetadata within GCP Audit Logs)
Changes made to an instance, including its settings and/or control data (ex: instance.addResourcePolicies or instances.setMetadata within GCP Audit Logs)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
.004 | Revert Cloud Instance |
Activation or invocation of an instance (ex: instance.start within GCP Audit Logs)
Activation or invocation of an instance (ex: instance.start within GCP Audit Logs)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
.004 | Revert Cloud Instance | ||
Enterprise | T1204 | User Execution | |
.003 | Malicious Image |
Deactivation or stoppage of an instance (ex: instance.stop within GCP Audit Logs)
Deactivation or stoppage of an instance (ex: instance.stop within GCP Audit Logs)
Domain | ID | Name | |
---|---|---|---|
Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
.004 | Revert Cloud Instance |