Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1526

T1526Cloud Service Discovery

T1526 — Cloud Service Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 18 detection use cases covering it and 6 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
18Use cases
6Articles
0Sub-techniques
1Tactic

Use cases covering this technique (18)

Unauthenticated route returns sensitive PII Internal delivery · alerting DD AWS CloudTrail AccessDenied spike Internal delivery · alerting DD Amazon EKS Kubernetes cluster scan detection ESCU actions · hunting P Amazon EKS Kubernetes Pod scan detection ESCU actions · hunting P AWS Excessive Security Scanning ESCU actions · alerting P Azure AD AzureHound UserAgent Detected ESCU actions · alerting P Azure AD Service Principal Enumeration ESCU actions · alerting P GCP Kubernetes cluster pod scan detection ESCU actions · hunting P Kubernetes Scanner Image Pulling ESCU actions · alerting P Kubernetes Suspicious Image Pulling ESCU actions · hunting P ASL AWS Excessive Security Scanning ESCU actions · hunting P GCP Kubernetes cluster scan detection ESCU actions · alerting P Kubernetes Azure scan fingerprint ESCU actions · hunting P [LLM] First-time Entra directory enumeration via Graph/PowerShell CLI tooling by a user Bespoke actions · hunting DSPDD [LLM] Traefik dynamic config write introducing unbounded ReplacePathRegex capture group Bespoke weapon · hunting DSΣPCS [LLM] Malicious vault-addr annotation on ConfigMap/Secret admission (CVE-2026-54725) Bespoke delivery · alerting SΣPDD [LLM] n8n-MCP cross-tenant workflow version read/enumeration via n8n_workflow_versions (CVE-2026-54052) Bespoke recon · hunting SP [LLM] Anonymous access to Kubernetes aggregated API (CVE-2018-1002105 exploit surface) Bespoke exploit · hunting SΣPDDCW

Articles citing this technique (6)