- AN1127 · Analytic 1127 — Unusual enumeration of services and resources through cloud APIs such as AWS CLI `describe-*`, Azure Resource Manager queries, or GCP project listings. Defender perspective includes anomalous API calls, unexpected volume of service enumeration, and correlation of discovery with recently compromised sessions.
- AN1128 · Analytic 1128 — Enumeration of directories, applications, or service principals through APIs such as Microsoft Graph or Okta API. Defender perspective includes unexpected listing of users, roles, applications, and abnormal access to identity management endpoints.
- AN1129 · Analytic 1129 — Discovery of SaaS services connected to productivity platforms (e.g., Microsoft 365, Google Workspace). Defender perspective includes unexpected enumeration of enabled services, API integrations, or OAuth applications tied to user accounts.
- AN1130 · Analytic 1130 — Discovery of connected SaaS applications, APIs, or configurations within platforms like Salesforce, Slack, or Zoom. Defender perspective includes enumeration of available integrations, abnormal querying of service metadata, and follow-on attempts to exploit or persist via discovered services.
AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Cloud Service Discovery
An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or software-as-a-service (SaaS). Many services exist throughout the various cloud providers and can include Continuous Integration and Continuous Delivery (CI/CD), Lambda Functions, Entra ID, etc. They may also include security services, such as AWS GuardDuty and Microsoft Defender for Cloud, and logging services, such as AWS CloudTrail and Google Cloud Audit Logs. Adversaries may attempt to discover information about the services enabled throughout the environment. Azure tools and APIs, such as the Microsoft Graph API and Azure Resource Manager API, can enumerate resources and services, including applications, management groups, resources and policy definitions, and their relationships that are accessible by an identity. For example, Stormspotter is an open source tool for enumerating and constructing a graph for Azure resources and services, and Pacu is an open source AWS exploitation framework that supports several methods for discovering cloud services. Adversaries may use the information gained to shape follow-on behaviors, such as targeting data or credentials from enumerated services or evading identified defenses through Disable or Modify Tools or Disable or Modify Cloud Logs.
Open detection, hunting, mitigation, and evidence workspace
Detection logic
Cloud service discovery techniques will likely occur throughout an operation where an adversary is targeting cloud-based systems and services. Data and events should not be viewed in isolation, but as part of a chain of behavior that could lead to other activities based on the information obtained. Normal, benign system and network events that look like cloud service discovery may be uncommon, depending on the environment and how they are used. Monitor cloud service usage for anomalous behavior that may indicate adversarial presence within the environment.
Observed actors
Correlated CTI and IR reports
Cyber Knowledge context
Use these routes to move from the ATT&CK behavior into explanation, implementation, evidence handling, validation, and defensive operations. Relevance is generated from explicit identifiers/names and governed topic mappings; it is not attribution evidence.
Cloud Security · Governed topic match · 88/100Data classification, storage, cryptography, keys, backup, and deletion
Cloud Security · Governed topic match · 81/100Organizations, landing zones, policy, inventory, and cost guardrails
Cloud Security · Governed topic match · 78/100Network, edge, service communication, hybrid access, and zero trust
Cloud Security · Governed topic match · 78/100Kubernetes control plane, RBAC, workload, network, and admission security
Cloud Security · Governed topic match · 78/100Multi-cloud, SaaS, suppliers, compliance, and continuous assurance
Cloud Security · Governed topic match · 78/100Shared responsibility, governance, and service ownership
Cloud Security · Governed topic match · 69/100Cloud logging, detection engineering, ATT CK, and response automation
Cloud Security · Governed topic match · 69/100Module 10 — Cloud, containers, Kubernetes, and SaaS defense
Blue Team & Defensive Security · Governed topic match · 63/100Module 2 — Reconnaissance and attack-surface mapping
Red Team & Offensive Security · Governed topic match · 54/100Module 2 — Asset, service, identity, and exposure context
Blue Team & Defensive Security · Governed topic match · 54/100Module 12 — Incident response, DFIR, crisis coordination, and recovery
Blue Team & Defensive Security · Governed topic match · 51/100
MITRE mitigations
No ATT&CK mitigation relationship is published for this technique. Apply risk-based controls and verify scope.