Modify Cloud Compute Infrastructure: Revert Cloud Instance T1578.004

Tactic: Defense Impairment

An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence. In highly virtualized environments, such as cloud-based infrastructure, this may be accomplished by restoring virtual machine (VM) or data storage snapshots through the cloud management dashboard or cloud APIs.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1in 1restoredbinstancefromdbsnapshot, restoredbinstancefroms3
Provider_Name1eq 1rds.amazonaws.com
data_stream.dataset1eq 1aws.cloudtrail
event.outcome1eq 1success

Top indicator values (5 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
restoredbinstancefromdbsnapshot
1
EventTypein
restoredbinstancefroms3
1
Provider_Nameeq
rds.amazonaws.com
19
data_stream.dataseteq
aws.cloudtrail
1173
event.outcomeeq
success
1375

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: AWS

Domain: Cloud

Elastic 1 rule