1200KM / detection
T1069.003 Cloud Groups — Detection Rules
Detection workspace for T1069.003 Cloud Groups: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- RBAC Permission Enumeration Attempt · test · low · {"category":"application","product":"kubernetes","service":"audit"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0251 Behavioral Detection of Cloud Group Enumeration via API and CLI Access
AN0695 Analytic 0695
Detects adversarial use of cloud-native APIs (e.g., AWS IAM, Azure RBAC, GCP Identity) to enumerate cloud group memberships or policy mappings via unauthorized sessions or scripts.
AN0696 Analytic 0696
Identifies unauthorized access or enumeration of administrative roles, security groups, or distribution groups via Exchange/SharePoint/Teams APIs or role discovery scripts.
AN0697 Analytic 0697
Monitors API calls and service-specific logs for enumeration of organizational roles, permissions, and group structure, particularly outside of normal admin behavior baselines.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.