{"id":"T1496.004","name":"Cloud Service Hijacking","url":"https://attack.mitre.org/techniques/T1496/004","tactics":["impact"],"platforms":["SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0147","stix_id":"x-mitre-detection-strategy--e769419e-39f6-478d-97b8-cf0672fa635b","name":"Detection Strategy for Cloud Service Hijacking via SaaS Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0147","analytics":[{"id":"AN0417","stix_id":"x-mitre-analytic--01967eb2-5169-4113-aff0-ac2180fd14d9","name":"Analytic 0417","description":"Adversary gains access to cloud-hosted services such as AWS SES, SNS, or OpenAI API, enables or modifies usage policies, and initiates resource-intensive actions (e.g., mass email/SMS or LLM queries), often from unauthorized regions or under anomalous identity conditions.","url":"https://attack.mitre.org/detectionstrategies/DET0147#AN0417","platforms":["SaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"PutIdentityPolicy","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"SendEmail","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"AssumeRole","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"TimeWindow","description":"Define threshold period over which request spikes are measured. E.g., 10 min or 1 hour windows."},{"field":"UserContext","description":"Alert only if role/user is outside expected automation identity list."},{"field":"RequestVolumeThreshold","description":"Customize the number of emails/SMS or API calls considered anomalous."},{"field":"GeoVelocityThreshold","description":"Tune geolocation jump logic (e.g., login from US, then use service in Asia within minutes)."},{"field":"ModelUsageQuotaSpike","description":"Set maximum allowable deviation from past 7-day average OpenAI/GPT token usage."}],"live":true,"detection_strategies":["DET0147"],"techniques":["T1496.004"]}],"live":true,"version":"1.0","techniques":["T1496.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}