Techniques › T1648
T1648 Serverless Execution
execution — SaaS, IaaS, Office Suite · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
0
Sigma rules tagged attack.t1648
0
KEV CVEs mapped here
<p>Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments. Many cloud providers offer a variety of serverless resources, including compute engines, application integration services, and web servers.</p><p>Adversaries may abuse these resources in various ways as a means of executing arbitrary commands. For example, adversaries may use serverless functions to execute malicious code, such as crypto-mining malware (i.e. Resource Hijacking). Adversaries may also create functions that enable further compromise of the cloud environment. For example, an adversary may use the
IAM:PassRole permission in AWS or the iam.serviceAccounts.actAs permission in Google Cloud to add Additional Cloud Roles to a serverless cloud function, which may then be able to perform actions the original user cannot.</p><p>Serverless functions can also be invoked in response to cloud events (i.e. Event Triggered Execution), potentially enabling persistent execution over time. For example, in AWS environments, an adversary may create a Lambda function that automatically adds Additional Cloud Credentials to a user and a corresponding CloudWatch events rule that invokes that function whenever a new user is created. This is also possible in many cloud-based office application suites. For example, in Microsoft 365 environments, an adversary may create a Power Automate workflow that forwards all emails a user receives or creates anonymous sharing links whenever a user is granted access to a document in SharePoint. In Google Workspace environments, they may instead create an Apps Script that exfiltrates a user's data when they open a file.</p>KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0374 Detection Strategy for Serverless Execution (T1648) v1.0
AN1053 IaaSCorrelate creation or modification of serverless functions (e.g., AWS Lambda, GCP Cloud Functions, Azure Functions) with anomalous IAM role assignments or permissions escalation events. Detect subsequent executions of newly created functions that perform unexpected actions such as spawning outbound network connections, accessing sensitive resources, or creating additional credentials.AWS:CloudTrail
CreateFunction / UpdateFunctionConfiguration: Function creation, role assignment, or configuration change events→ DC0069 Cloud Service ModificationAWS:CloudTrailInvokeFunction: Unexpected or repeated invocation of functions not tied to known workflows→ DC0038 Application Log ContentTunable:RoleScopeAllowedFunctionsTimeWindowAN1054 Office SuiteMonitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints.m365:unifiedAddFlow / UpdateFlow: New automation or workflow creation events→ DC0069 Cloud Service Modificationm365:exchangeNew-InboxRule: Automation that triggers abnormal forwarding or external link generation→ DC0038 Application Log ContentTunable:UserContextFlowActionsAN1055 SaaSTrack creation or update of SaaS automation scripts (e.g., Google Workspace Apps Script). Detect when these scripts are bound to user events such as file opens or account modifications, and correlate with subsequent abnormal API calls that exfiltrate or modify user data.saas:appsscriptCreate / Update: Deployment of scripts with event-driven triggers→ DC0069 Cloud Service Modificationsaas:googledriveFileOpen / FileAccess: Event-driven script triggering on user file actions→ DC0038 Application Log ContentTunable:ScriptScopeTriggerTypes
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1648
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.