T1069.003sub-technique of T1069 Permission Groups Discovery
Cloud Groups
SaaS · IaaS · Office Suite · Identity Providernothing on this site yetT1069.003 on attack.mitre.org
Adversaries may attempt to find cloud groups and permission settings. The knowledge of cloud permission groups can help adversaries determine the particular roles of users and groups within an environment, as well as which users are associated with a particular group. With authenticated access there are several tools that can be used to find permissions groups.
how MITRE says to see it
Behavioral Detection of Cloud Group Enumeration via API and CLI Access
- Detects adversarial use of cloud-native APIs (e.g., AWS IAM, Azure RBAC, GCP Identity) to enumerate cloud group memberships or policy mappings via unauthorized sessions or scripts.
- Identifies unauthorized access or enumeration of administrative roles, security groups, or distribution groups via Exchange/SharePoint/Teams APIs or role discovery scripts.
- Monitors API calls and service-specific logs for enumeration of organizational roles, permissions, and group structure, particularly outside of normal admin behavior baselines.