1200KM / detection
T1059.009 Cloud API — Detection Rules
Detection workspace for T1059.009 Cloud API: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS IAM S3Browser LoginProfile Creation · test · high · {"product":"aws","service":"cloudtrail"}
- AWS IAM S3Browser Templated S3 Bucket Policy Creation · test · high · {"product":"aws","service":"cloudtrail"}
- AWS IAM S3Browser User or AccessKey Creation · test · high · {"product":"aws","service":"cloudtrail"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0078 Behavioral Detection of Malicious Cloud API Scripting
AN0215 Analytic 0215
Detects adversarial use of cloud APIs for command execution, resource control, or reconnaissance. Focuses on CLI/SDK/scripting language abuse via stolen credentials or in-browser Cloud Shells. Monitors for anomalous API calls chained with authentication context shifts (e.g., stolen token -> privileged action) and cross-service impacts.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.