Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1526

T1526Cloud Service Discovery

T1526 — Cloud Service Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 15 detection use cases covering it and 2 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
2Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Unauthenticated route returns sensitive PII Internal delivery · alerting DD AWS CloudTrail AccessDenied spike Internal delivery · alerting DD Amazon EKS Kubernetes cluster scan detection ESCU actions · hunting P Amazon EKS Kubernetes Pod scan detection ESCU actions · hunting P AWS Excessive Security Scanning ESCU actions · alerting P Azure AD AzureHound UserAgent Detected ESCU actions · alerting P Azure AD Service Principal Enumeration ESCU actions · alerting P GCP Kubernetes cluster pod scan detection ESCU actions · hunting P Kubernetes Scanner Image Pulling ESCU actions · alerting P Kubernetes Suspicious Image Pulling ESCU actions · hunting P ASL AWS Excessive Security Scanning ESCU actions · hunting P GCP Kubernetes cluster scan detection ESCU actions · alerting P Kubernetes Azure scan fingerprint ESCU actions · hunting P [LLM] nebula-mesh CVE-2026-47724 — operator roster + API key metadata enumeration burst Bespoke recon · hunting SPDD [LLM] Bun/Node initiating multi-cloud secret-manager enumeration burst (Sha1-Hulud aL0 harvest) Bespoke actions · alerting DSPDDCS

Articles citing this technique (2)