MITRE ATT&CK technique
Modify Cloud Compute Infrastructure detection rulesT1578
Modify Cloud Compute Infrastructure (T1578) is a MITRE ATT&CK technique in the Defense Impairment tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1578 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target azure.
Top products
Tactic
Azure Active Directory Hybrid Health AD FS New Server
mediumThis detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.
azure
Azure Active Directory Hybrid Health AD FS Service Delete
mediumThis detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.
azure