Unsecured Credentials: Cloud Instance Metadata API T1552.005
Tactic: Credential Access
Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 3 | Network connection |
| ESF | exec | Process Execution |
Authoring guide
These 20 rules share fields, values, and exclusions.
Fields filtered most (34 distinct)
These fields appear most often in rule filters.
Top indicator values (266 distinct)
These values appear most often in rule predicates.
Exclusions (28 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Elastic 19 rules
- AWS Bedrock AgentCore Execution Role Used Outside Its Runtime
- AWS Bedrock AgentCore Runtime Prompt Targeting Credentials or Instance Metadata
- AWS EC2 Instance Console Login via Assumed Role
- AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role
- AWS EC2 User Data Retrieval for EC2 Instance
- Azure Event Hub Authorization Rule Created or Updated
- Azure Storage Account Key Regenerated
- Bun Script Attempted to Access IMDS Metadata
- Bun Script Attempted to Access IMDS Metadata
- Cloud Instance Metadata Credential Path HTTP Request
- GKE Pod Exec Cloud Instance Metadata Access
- Kubernetes Pod Exec Cloud Instance Metadata Access
- Suspicious Instance Metadata Service (IMDS) API Command Line Execution
- Suspicious Instance Metadata Service (IMDS) API Request
- Unusual Linux Process Calling the Metadata Service
- Unusual Linux User Calling the Metadata Service
- Unusual Windows Process Calling the Metadata Service
- Unusual Windows User Calling the Metadata Service
- Web Server Cloud Metadata SSRF Request