{"id":"T1578.003","name":"Delete Cloud Instance","url":"https://attack.mitre.org/techniques/T1578/003","tactics":["defense-impairment"],"platforms":["IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0084","stix_id":"x-mitre-detection-strategy--ceac3cb0-d9eb-4466-810f-4acbf793e980","name":"Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance","url":"https://attack.mitre.org/detectionstrategies/DET0084","analytics":[{"id":"AN0234","stix_id":"x-mitre-analytic--602def5b-49e4-4c64-afe6-1476eac13e67","name":"Analytic 0234","description":"Defenders can detect suspicious cloud instance deletions by correlating events across authentication, instance lifecycle, and account activity. From a defender’s perspective, behaviors of interest include instances deleted shortly after creation, deletions initiated by new or rarely used accounts, deletions following snapshot creation, and deletions originating from anomalous geolocations or access keys. These may indicate adversarial attempts to destroy forensic evidence or evade detection.","url":"https://attack.mitre.org/detectionstrategies/DET0084#AN0234","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"TerminateInstances","data_component":"DC0089","data_component_name":"Instance Stop","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"DescribeInstances","data_component":"DC0086","data_component_name":"Instance Metadata","log_source_slug":"aws-cloudtrail"},{"name":"azure:activity","channel":"MICROSOFT.COMPUTE/VIRTUALMACHINES/DELETE","data_component":"DC0081","data_component_name":"Instance Deletion","log_source_slug":"azure-activity"}],"mutable_elements":[{"field":"UserContext","description":"Identity of the user/service account performing deletions; tuned to exclude automation or known administrative workflows."},{"field":"TimeWindow","description":"Threshold for detecting rapid instance lifecycle events (e.g., creation and deletion within minutes)."},{"field":"GeoLocation","description":"Region or source IP where the delete request originated; can be tuned to align with enterprise cloud geography."},{"field":"RateThreshold","description":"Number of deletions per user/account in a defined window; tuned for organizations with high elasticity."}],"live":true,"detection_strategies":["DET0084"],"techniques":["T1578.003"]}],"live":true,"version":"1.0","techniques":["T1578.003"]}],"sigma_rules":[{"id":"48739819-8230-4ee3-a8ea-e0289d1fb0ff","title":"Azure Active Directory Hybrid Health AD FS Service Delete","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC","status":"test","level":"medium","date":"2021-08-26","modified":"2023-10-11","description":"This detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant.\nA threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs.\nThe health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.\n","references":["https://o365blog.com/post/hybridhealthagent/"],"logsource":{"product":"azure","service":"activitylogs"},"tags":["attack.defense-impairment","attack.t1578.003"],"path":"rules/cloud/azure/activity_logs/azure_aadhybridhealth_adfs_service_delete.yml","techniques":["T1578.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}