1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1021.007 Cloud Services — Detection Rules

Detection workspace for T1021.007 Cloud Services: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0008 Behavioral Detection of Remote Cloud Logins via Valid Accounts

AN0017 Analytic 0017

Cloud login from atypical geolocation or user-agent string, followed by resource enumeration or infrastructure manipulation using cloud CLI/API

AN0018 Analytic 0018

Federated login using SSO or OAuth grant to cloud control plane, followed by directory or permissions enumeration

AN0019 Analytic 0019

Login to M365 or Google Workspace from CLI tools or unexpected source IPs, followed by mailbox or document access

AN0020 Analytic 0020

Remote access to third-party SaaS with OAuth or API tokens post-initial compromise, followed by sensitive data access or configuration changes

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1021.007 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.