Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552.005

T1552.005Cloud Instance Metadata API

T1552.005 — Cloud Instance Metadata API is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 17 detection use cases covering it and 10 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
17Use cases
10Articles
0Sub-techniques
1Tactic

Use cases covering this technique (17)

[WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Cisco Isovalent - Access To Cloud Metadata Service ESCU actions · hunting P [LLM] Enterprise Gateway service account creates privileged / hostPath / RBAC-escalating pod (CVE-2026-44181 post-exploit) Bespoke actions · alerting SΣPDDCW [LLM] Enterprise Gateway python container spawns shell or reads K8s service-account token (CVE-2026-44181 RCE) Bespoke install · alerting DSΣPDDCS [LLM] GitHub Actions Runner.Worker process-memory secret scraping (Miasma payload) Bespoke actions · alerting DSΣPDDCS [LLM] Cloud IMDS credential harvesting from node/bun process on CI runner Bespoke actions · alerting DSΣPDDCSCW [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) Bespoke actions · hunting DSPDDCS [LLM] Cloud metadata service hit (IMDSv2 / ECS) from node process under node_modules Bespoke actions · alerting DSΣPDDCSCW [LLM] Package-manager process harvesting cloud metadata / Vault (IMDS 169.254.169.254, ECS 169.254.170.2, Vault :8200) Bespoke actions · hunting DSPDDCS [LLM] nezha-agent spawning credential-access shell commands on Linux (post-RCE) Bespoke actions · alerting DSΣPDDCS [LLM] nezha-agent outbound network connection to cloud instance-metadata service Bespoke actions · alerting DSΣPDDCS [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Bun/Node initiating multi-cloud secret-manager enumeration burst (Sha1-Hulud aL0 harvest) Bespoke actions · alerting DSPDDCS [LLM] Cloud metadata service (IMDS) access from npm / node child process Bespoke actions · alerting DSPDDCS

Articles citing this technique (10)