Loading interactive filters…
1200KM / detection
T1648 Serverless Execution — Detection Rules
Detection workspace for T1648 Serverless Execution: 0 Sigma sources, 0 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
Unexpected serverless or cloud-workload invocation — T1648 Serverless Execution
Comparison unit: function, caller, and trigger.
Expected behavior: functions are invoked by known trigger and caller combinations with stable rates.
Deviation: new caller-trigger edge, burst, or invocation outside established temporal context.
ATT&CK analytic guidance
Correlate creation or modification of serverless functions (e.g., AWS Lambda, GCP Cloud Functions, Azure Functions) with anomalous IAM role assignments or permissions escalation events. Detect subsequent executions of newly created functions that perform unexpected actions such as spawning outbound network connections, accessing sensitive resources, or creating additional credentials.
Monitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints.
Track creation or update of SaaS automation scripts (e.g., Google Workspace Apps Script). Detect when these scripts are bound to user events such as file opens or account modifications, and correlate with subsequent abnormal API calls that exfiltrate or modify user data.
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.