1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1496.004 Cloud Service Hijacking — Detection Rules

Detection workspace for T1496.004 Cloud Service Hijacking: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0147 Detection Strategy for Cloud Service Hijacking via SaaS Abuse

AN0417 Analytic 0417

Adversary gains access to cloud-hosted services such as AWS SES, SNS, or OpenAI API, enables or modifies usage policies, and initiates resource-intensive actions (e.g., mass email/SMS or LLM queries), often from unauthorized regions or under anomalous identity conditions.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1496.004 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.