Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
5 Days |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
A compute resource was created or updated in a cloud region that has been dormant for this project.
Attacker's Goals
Create compute resources in unmonitored regions to evade detection for purposes such as hijacking resources or establishing persistence.
Investigative actions
- Verify if compute resources are authorized in this region.
- Terminate unauthorized compute resources and disable unused regions.
Variations
Compute activity in dormant cloud region from a non-VPN IP addressA cloud compute instance was created in a dormant region
Compute activity in dormant cloud region by a compromised AWS access key