1200KM / detection
T1578 Modify Cloud Compute Infrastructure — Detection Rules
Detection workspace for T1578 Modify Cloud Compute Infrastructure: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Azure Active Directory Hybrid Health AD FS New Server · test · medium · {"product":"azure","service":"activitylogs"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0308 Detection Strategy for Modify Cloud Compute Infrastructure
AN0861 Analytic 0861
Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Cloud Service Metadata · DC0070
- Instance Start · DC0080
- Instance Stop · DC0089
- Snapshot Creation · DC0057
- Snapshot Deletion · DC0049
- Snapshot Modification · DC0058
- Volume Creation · DC0097
- Volume Deletion · DC0098
- Volume Modification · DC0092
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.