T1578.005sub-technique of T1578 Modify Cloud Compute Infrastructure
Modify Cloud Compute Configurations
IaaSnothing on this site yetT1578.005 on attack.mitre.org
Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses. These settings may include service quotas, subscription associations, tenant-wide policies, or other configurations that impact available compute.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Ransomware, suspected or confirmed
Files renamed or unreadable, a ransom note, or backup deletion commands seen.
how MITRE says to see it
Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
- Defenders should monitor for anomalous or unauthorized changes to cloud compute configurations that alter quotas, tenant-wide policies, subscription associations, or allowed deployment regions.
what reduces it
- M1018 User Account Management. Limit permissions to request quotas adjustments or modify tenant-level compute setting to only those required.
- M1047 Audit. Routinely monitor user permissions to ensure only the expected users have the capability to request quota adjustments or modify tenant-level compute settings.