Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access T1548.005
Tactic: Privilege Escalation
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto resources and services, or otherwise gain short-term access to a set of privileges that may be distinct from their own.
Authoring guide
These 7 rules share fields, values, and exclusions.
Fields filtered most (8 distinct)
These fields appear most often in rule filters.
Top indicator values (29 distinct)
These values appear most often in rule predicates.
Exclusions (12 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: AWS
Domain: Cloud
Elastic 7 rules
- AWS EC2 Instance Profile Associated with Running Instance
- AWS IAM Customer Managed Policy Version Created or Default Version Set
- AWS IAM Customer-Managed Policy Attached to Role by Rare User
- AWS KMS Key Policy Updated via PutKeyPolicy
- AWS STS AssumeRoot by Rare User and Member Account
- AWS STS GetFederationToken with AdministratorAccess in Request
- AWS STS Role Assumption by Service