Esc
Create Cloud Instance - T1578.002
(ATT&CK® Technique)
Definition
An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new instance may allow an adversary to bypass firewall rules and permissions that exist on instances currently residing within an account. An adversary may Create Snapshot of one or more volumes in an account, create a new instance, mount the snapshots, and then apply a less restrictive security policy to collect Data from Local System or for Remote Data Staging.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.