1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1069.003 Cloud Groups — Detection Rules

Detection workspace for T1069.003 Cloud Groups: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0251 Behavioral Detection of Cloud Group Enumeration via API and CLI Access

AN0695 Analytic 0695

Detects adversarial use of cloud-native APIs (e.g., AWS IAM, Azure RBAC, GCP Identity) to enumerate cloud group memberships or policy mappings via unauthorized sessions or scripts.

AN0696 Analytic 0696

Identifies unauthorized access or enumeration of administrative roles, security groups, or distribution groups via Exchange/SharePoint/Teams APIs or role discovery scripts.

AN0697 Analytic 0697

Monitors API calls and service-specific logs for enumeration of organizational roles, permissions, and group structure, particularly outside of normal admin behavior baselines.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1069.003 simulation workspace

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.