Files
atomic-red-team/atomics/Indexes/Indexes-CSV/iaas-index.csv
T
2023-11-07 00:28:51 +00:00

5.9 KiB

1TacticTechnique #Technique NameTest #Test NameTest GUIDExecutor Name
2defense-evasionT1562.001Impair Defenses: Disable or Modify Tools46AWS - GuardDuty Suspension or Deletion11e65d8d-e7e4-470e-a3ff-82bc56ad938ebash
3defense-evasionT1562.008Impair Defenses: Disable Cloud Logs1AWS - CloudTrail Changes9c10dc6b-20bd-403a-8e67-50ef7d07ed4esh
4defense-evasionT1562.008Impair Defenses: Disable Cloud Logs2Azure - Eventhub Deletion5e09bed0-7d33-453b-9bf3-caea32bff719powershell
5defense-evasionT1562.008Impair Defenses: Disable Cloud Logs4AWS - Disable CloudTrail Logging Through Event Selectors using Stratusa27418de-bdce-4ebd-b655-38f11142bf0csh
6defense-evasionT1562.008Impair Defenses: Disable Cloud Logs6AWS - Remove VPC Flow Logs using Stratus93c150f5-ad7b-4ee3-8992-df06dec2ac79sh
7defense-evasionT1562.008Impair Defenses: Disable Cloud Logs7AWS - CloudWatch Log Group Deletes89422c87-b57b-4a04-a8ca-802bb9d06121sh
8defense-evasionT1562.008Impair Defenses: Disable Cloud Logs8AWS CloudWatch Log Stream Deletes33ca84bc-4259-4943-bd36-4655dc420932sh
9defense-evasionT1562.008Impair Defenses: Disable Cloud Logs10GCP - Delete Activity Event Logd56152ec-01d9-42a2-877c-aac1f6ebe8e6sh
10defense-evasionT1078.004Valid Accounts: Cloud Accounts1Creating GCP Service Account and Service Account Key9fdd83fd-bd53-46e5-a716-9dec89c8ae8esh
11defense-evasionT1078.004Valid Accounts: Cloud Accounts2Azure Persistence Automation Runbook Created or Modified348f4d14-4bd3-4f6b-bd8a-61237f78b3acpowershell
12defense-evasionT1078.004Valid Accounts: Cloud Accounts3GCP - Create Custom IAM Role3a159042-69e6-4398-9a69-3308a4841c85sh
13credential-accessT1552.005Unsecured Credentials: Cloud Instance Metadata API2Azure - Dump Azure Instance Metadata from Virtual Machinescc99e772-4e18-4f1f-b422-c5cdd1bfd7b7powershell
14credential-accessT1552Unsecured Credentials1AWS - Retrieve EC2 Password Data using stratusa21118de-b11e-4ebd-b655-42f11142df0csh
15credential-accessT1110.003Brute Force: Password Spraying9AWS - Password Spray an AWS using GoAWSConsoleSpray9c10d16b-20b1-403a-8e67-50ef7117ed4esh
16impactT1485Data Destruction4GCP - Delete Bucket4ac71389-40f4-448a-b73f-754346b3f928sh
17discoveryT1580Cloud Infrastructure Discovery1AWS - EC2 Enumeration from Cloud Instance99ee161b-dcb1-4276-8ecb-7cfdcb207820sh
18discoveryT1619Cloud Storage Object Discovery1AWS S3 Enumeration3c7094f8-71ec-4917-aeb8-a633d7ec4ef5sh
19discoveryT1201Password Policy Discovery12Examine AWS Password Policy15330820-d405-450b-bd08-16b5be5be9f4sh
20discoveryT1526Cloud Service Discovery1Azure - Dump Subscription Data with MicroBurst1e40bb1d-195e-401e-a86b-c192f55e005cpowershell
21persistenceT1098.001Account Manipulation: Additional Cloud Credentials3AWS - Create Access Key and Secret Key8822c3b0-d9f9-4daf-a043-491160a31122sh
22persistenceT1136.003Create Account: Cloud Account1AWS - Create a new IAM user8d1c2368-b503-40c9-9057-8e42f21c58adsh
23persistenceT1098Account Manipulation3AWS - Create a group and add a user to that group8822c3b0-d9f9-4daf-a043-49f110a31122sh
24persistenceT1098Account Manipulation6Azure - adding user to Azure role in subscription1a94b3fc-b080-450a-b3d8-6d9b57b472eapowershell
25persistenceT1098Account Manipulation7Azure - adding service principal to Azure role in subscriptionc8f4bc29-a151-48da-b3be-4680af56f404powershell
26persistenceT1098Account Manipulation17GCP - Delete Service Account Key7ece1dea-49f1-4d62-bdcc-5801e3292510sh
27persistenceT1078.004Valid Accounts: Cloud Accounts1Creating GCP Service Account and Service Account Key9fdd83fd-bd53-46e5-a716-9dec89c8ae8esh
28persistenceT1078.004Valid Accounts: Cloud Accounts2Azure Persistence Automation Runbook Created or Modified348f4d14-4bd3-4f6b-bd8a-61237f78b3acpowershell
29persistenceT1078.004Valid Accounts: Cloud Accounts3GCP - Create Custom IAM Role3a159042-69e6-4398-9a69-3308a4841c85sh
30privilege-escalationT1098.001Account Manipulation: Additional Cloud Credentials3AWS - Create Access Key and Secret Key8822c3b0-d9f9-4daf-a043-491160a31122sh
31privilege-escalationT1098Account Manipulation3AWS - Create a group and add a user to that group8822c3b0-d9f9-4daf-a043-49f110a31122sh
32privilege-escalationT1098Account Manipulation6Azure - adding user to Azure role in subscription1a94b3fc-b080-450a-b3d8-6d9b57b472eapowershell
33privilege-escalationT1098Account Manipulation7Azure - adding service principal to Azure role in subscriptionc8f4bc29-a151-48da-b3be-4680af56f404powershell
34privilege-escalationT1098Account Manipulation17GCP - Delete Service Account Key7ece1dea-49f1-4d62-bdcc-5801e3292510sh
35privilege-escalationT1078.004Valid Accounts: Cloud Accounts1Creating GCP Service Account and Service Account Key9fdd83fd-bd53-46e5-a716-9dec89c8ae8esh
36privilege-escalationT1078.004Valid Accounts: Cloud Accounts2Azure Persistence Automation Runbook Created or Modified348f4d14-4bd3-4f6b-bd8a-61237f78b3acpowershell
37privilege-escalationT1078.004Valid Accounts: Cloud Accounts3GCP - Create Custom IAM Role3a159042-69e6-4398-9a69-3308a4841c85sh
38collectionT1530Data from Cloud Storage Object1Azure - Enumerate Azure Blobs with MicroBurst3dab4bcc-667f-4459-aea7-4162dd2d6590powershell
39collectionT1530Data from Cloud Storage Object2Azure - Scan for Anonymous Access to Azure Storage (Powershell)146af1f1-b74e-4aa7-9895-505eb559b4b0powershell
40collectionT1530Data from Cloud Storage Object3AWS - Scan for Anonymous Access to S3979356b9-b588-4e49-bba4-c35517c484f5sh
41initial-accessT1078.004Valid Accounts: Cloud Accounts1Creating GCP Service Account and Service Account Key9fdd83fd-bd53-46e5-a716-9dec89c8ae8esh
42initial-accessT1078.004Valid Accounts: Cloud Accounts2Azure Persistence Automation Runbook Created or Modified348f4d14-4bd3-4f6b-bd8a-61237f78b3acpowershell
43initial-accessT1078.004Valid Accounts: Cloud Accounts3GCP - Create Custom IAM Role3a159042-69e6-4398-9a69-3308a4841c85sh