Initial construction of a new instance (ex: instance.insert within GCP Audit Logs)
Initial construction of a new instance (ex: instance.insert within GCP Audit Logs)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
| .002 | Create Cloud Instance | ||
| Enterprise | T1535 | Unused/Unsupported Cloud Regions | |
| Enterprise | T1204 | User Execution | |
| .003 | Malicious Image | ||
Removal of an instance (ex: instance.delete within GCP Audit Logs)
Removal of an instance (ex: instance.delete within GCP Audit Logs)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1485 | Data Destruction | |
| Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
| .003 | Delete Cloud Instance | ||
An extracted list of instances within a cloud environment (ex: instance.list within GCP Audit Logs)
An extracted list of instances within a cloud environment (ex: instance.list within GCP Audit Logs)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1580 | Cloud Infrastructure Discovery | |
Contextual data about an instance and activity around it such as name, type, or status
Contextual data about an instance and activity around it such as name, type, or status
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1580 | Cloud Infrastructure Discovery | |
| Enterprise | T1082 | System Information Discovery | |
| Enterprise | T1614 | System Location Discovery | |
Changes made to an instance, including its settings and/or control data (ex: instance.addResourcePolicies or instances.setMetadata within GCP Audit Logs)
Changes made to an instance, including its settings and/or control data (ex: instance.addResourcePolicies or instances.setMetadata within GCP Audit Logs)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
| .004 | Revert Cloud Instance | ||
Activation or invocation of an instance (ex: instance.start within GCP Audit Logs)
Activation or invocation of an instance (ex: instance.start within GCP Audit Logs)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
| .004 | Revert Cloud Instance | ||
| Enterprise | T1204 | User Execution | |
| .003 | Malicious Image | ||
Deactivation or stoppage of an instance (ex: instance.stop within GCP Audit Logs)
Deactivation or stoppage of an instance (ex: instance.stop within GCP Audit Logs)
| Domain | ID | Name | |
|---|---|---|---|
| Enterprise | T1578 | Modify Cloud Compute Infrastructure | |
| .004 | Revert Cloud Instance | ||