1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1548.005 Temporary Elevated Cloud Access — Detection Rules

Detection workspace for T1548.005 Temporary Elevated Cloud Access: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0393 Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)

AN1105 Analytic 1105

Multiple AWS CloudTrail events indicating temporary privilege escalation via PassRole and AssumeRole targeting newly created services or non-interactive infrastructure.

AN1106 Analytic 1106

Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation.

AN1107 Analytic 1107

Detection of ApplicationImpersonation role assignment or delegated mailbox access to service principals or rarely used users, especially outside of normal hours or geographic norms.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1548.005 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.