Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1552 ✕
Download CSV Show ATT&CK heatmapUnusual cloud Instance Metadata Service (IMDS) access Informational Cloud 7 variations
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Cloud Instance Metadata API (T1552.005)Required data: XDR AgentDetector tags: Kubernetes - AGENT, Kubernetes Credentials Theft AnalyticsAttacker's goals: Extract sensitive cloud compute tokens to access restricted cloud resources.Investigative actions: Determine whether a web service was involved and if it was exploited to execute this technique. Identify any additional commands that were executed. Review the permissions assigned to the target machine to identify which resources may be affected. Examine related compute activity in the cloud audit logs.Variations
Unusual cloud Instance Metadata Service (IMDS) access from a lightweight JavaScript runtime executing a script
Medium overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden
Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows web service
Medium overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden
Unusual cloud Instance Metadata Service (IMDS) access from an unusual known web service
Medium overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden
Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows shell process
Medium overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden
Unusual cloud Instance Metadata Service (IMDS) access from an unusual known shell process
Medium overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden
Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows scripting process
Medium overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden
Unusual cloud Instance Metadata Service (IMDS) access from an unusual known scripting process
Low overridden
A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden