T1021.008sub-technique of T1021 Remote Services

Direct Cloud VM Connections

IaaSnothing on this site yetT1021.008 on attack.mitre.org

Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods. Many cloud providers offer interactive connections to virtual infrastructure that can be accessed through the Cloud API, such as Azure Serial Console, AWS EC2 Instance Connect, and AWS System Manager.. Methods of authentication for these connections can include passwords, application access tokens, or SSH keys.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

Playbook for this stage

Cloud account compromise

Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

how MITRE says to see it

Detection of Direct VM Console Access via Cloud-Native Methods

  • Direct login to cloud-hosted virtual machines via cloud-native access methods (e.g., EC2 Instance Connect, Azure Serial Console, SSM), followed by command execution or privilege escalation on the VM

what reduces it

  • M1018 User Account Management. Limit which users are allowed to access compute infrastructure via cloud native methods.
  • M1042 Disable or Remove Feature or Program. If direct virtual machine connections are not required for administrative use, disable these connection types where feasible.

the rest of T1021

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.