Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Execution

T1059.009 Cloud API

Sub-technique of T1059 Command and Scripting Interpreter

Adversaries may abuse cloud APIs to execute malicious commands. APIs available in cloud environments provide various functionalities and are a feature-rich method for programmatic access to nearly all aspects of a tenant. These APIs may be utilized through various methods such as command line interpreters (CLIs), in-browser Cloud Shells,…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.