Unsecured Credentials: Cloud Instance Metadata API T1552.005

Tactic: Credential Access

Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.

Events covered

2 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 3Network connection
ESFexecProcess Execution

Authoring guide

These 20 rules share fields, values, and exclusions.

Fields filtered most (34 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType7eq 4, in 4, wildcard 1exec, connection_attempted, start, ConsoleLogin, GetSigninToken
data_stream.dataset7eq 7aws.cloudtrail, azure.activitylogs, gcp.audit
event.outcome6eq 6success
process_name5eq 3, starts_with 2, in 1, wildcard 1bash, bun, ., bun.exe, .*
DestinationPort4eq 480
event.type4eq 4start
Image3wildcard 3, starts_with 1/.*, /boot/*, ./, ./*, /boot/
Provider_Name3eq 3ec2.amazonaws.com, signin.amazonaws.com
aws::userIdentity.type3eq 3assumedrole, AssumedRole
destination.address3eq 3169.254.169.254
azure.activitylogs.operation_name2eq 2microsoft.eventhub/namespaces/authorizationrules/write, microsoft.storage/storageaccounts/regeneratekey/action
dest_ip2eq 2169.254.169.254
host.os.type2in 2
Esql.executed_command1is_not_null 1, regex_match 1.*(169\.254\.169\.254|2852039166|0xa9fea9fe|/latest/api/t...
Esql_priv.aws_bedrock_agentcore_request_payload_prompt_lower1regex_match 1.*(169\.254\.169\.254|169\.254\.170\.2|/latest/meta-data|..., .*(aws_secret_access_key|aws_access_key_id|secret access..., .*(ignore (all )?(your )?(previous|prior|above)...

Top indicator values (266 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
6375
DestinationPorteq
80
413
data_stream.dataseteq
aws.cloudtrail
4173
data_stream.dataseteq
azure.activitylogs
239
event.typeeq
start
41087
Imagewildcard
/home/*/*
323
Imagewildcard
/.*
22
Imagewildcard
/boot/*
221
Imagewildcard
/dev/shm/*
230
Imagewildcard
/run/*
218
Imagewildcard
/tmp/*
234
Imagewildcard
/var/run/*
212
Imagewildcard
/var/tmp/*
232
Imagewildcard
?:\programdata\*
218
Imagewildcard
c:\users\*
22
destination.addresseq
169.254.169.254
33
process_nameeq
bun
34
process_nameeq
bun.exe
33
EventTypeeq
connection_attempted
275
EventTypein
exec
2206
EventTypein
start
2168
Provider_Nameeq
ec2.amazonaws.com
220
aws::userIdentity.typeeq
assumedrole
29
dest_ipeq
169.254.169.254
23
process_namestarts_with
.
238
process_namestarts_with
lua
230
process_namestarts_with
perl
236
process_namestarts_with
php
228
process_namestarts_with
python
271
process_namestarts_with
ruby
236

Exclusions (28 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinewildcard
bun --watch src/app.ts
2
CommandLinewildcard
bun packages/product-config/codegen/api-codegen.ts
2
CommandLinewildcard
bun run apps/backend/probe-pagination.ts
2
CommandLinewildcard
bun run scripts/ingest-resilience-retrospectives.ts --ingest
2
CommandLinewildcard
bun test src/integrations/__tests__/*
2
Imagewildcard
/vscode/vscode-server/bin/linux-x64/*/node
1
Provider_Namein
bedrock-agentcore-control.amazonaws.com
1
Provider_Namein
bedrock-agentcore.amazonaws.com
1
Provider_Namein
bedrock-runtime.amazonaws.com
1
Provider_Namein
bedrock.amazonaws.com
1
Provider_Namein
ecr-public.amazonaws.com
1
Provider_Namein
ecr.amazonaws.com
1
Provider_Namein
logs.amazonaws.com
1
Provider_Namein
monitoring.amazonaws.com
1
Provider_Namein
xray.amazonaws.com
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 19 rules

Splunk 1 rule