Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1526

T1526Cloud Service Discovery

T1526 — Cloud Service Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 15 detection use cases covering it and 3 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
3Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Unauthenticated route returns sensitive PII Internal delivery · alerting DD AWS CloudTrail AccessDenied spike Internal delivery · alerting DD Amazon EKS Kubernetes cluster scan detection ESCU actions · hunting P Amazon EKS Kubernetes Pod scan detection ESCU actions · hunting P AWS Excessive Security Scanning ESCU actions · alerting P Azure AD AzureHound UserAgent Detected ESCU actions · alerting P Azure AD Service Principal Enumeration ESCU actions · alerting P GCP Kubernetes cluster pod scan detection ESCU actions · hunting P Kubernetes Scanner Image Pulling ESCU actions · alerting P Kubernetes Suspicious Image Pulling ESCU actions · hunting P ASL AWS Excessive Security Scanning ESCU actions · hunting P GCP Kubernetes cluster scan detection ESCU actions · alerting P Kubernetes Azure scan fingerprint ESCU actions · hunting P [LLM] n8n-MCP cross-tenant workflow version read/enumeration via n8n_workflow_versions (CVE-2026-54052) Bespoke recon · hunting SP [LLM] Anonymous access to Kubernetes aggregated API (CVE-2018-1002105 exploit surface) Bespoke exploit · hunting SΣPDDCW

Articles citing this technique (3)