Resource Hijacking: Cloud Service Hijacking T1496.004

Tactic: Impact

Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability.

Authoring guide

These 5 rules share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType4eq 3, in 1createprovisionedmodelthroughput, createtopic, deleteprovisionedmodelthroughput, publish, subscribe
Provider_Name4eq 4sns.amazonaws.com, bedrock.amazonaws.com
data_stream.dataset4eq 4aws.cloudtrail
event.outcome4eq 4success
operation1in 1Converse, InvokeModel
output.outputBodyJson.usage.outputTokens1eq 10
output.outputBodyJson.usage.totalTokens1gt 11000

Top indicator values (14 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
data_stream.dataseteq
aws.cloudtrail
4173
event.outcomeeq
success
4375
Provider_Nameeq
sns.amazonaws.com
33
Provider_Nameeq
bedrock.amazonaws.com
116
EventTypeeq
createtopic
1
EventTypeeq
publish
1
EventTypeeq
subscribe
1
EventTypein
createprovisionedmodelthroughput
1
EventTypein
deleteprovisionedmodelthroughput
12
EventTypein
updateprovisionedmodelthroughput
1
operationin
Converse
1
operationin
InvokeModel
1
output.outputBodyJson.usage.outputTokenseq
0
1
output.outputBodyJson.usage.totalTokensgt
1000
1

Exclusions (1 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
aws::userAgentcontains
terraform
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: AWS

Domain: Cloud

Elastic 4 rules

Panther 1 rule