Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552.005

T1552.005Cloud Instance Metadata API

T1552.005 — Cloud Instance Metadata API is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 23 detection use cases covering it and 16 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
23Use cases
16Articles
0Sub-techniques
1Tactic

Use cases covering this technique (23)

[WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Cisco Isovalent - Access To Cloud Metadata Service ESCU actions · hunting P [LLM] Cloud instance metadata (IMDS 169.254.169.254) queried by a recon tool inside a workload Bespoke actions · hunting DSΣPDDCS [LLM] Fluentd aggregator pod reaches cloud IMDS 169.254.169.254 (credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Prebid-server access to cloud metadata service (169.254.169.254) via SSRF Bespoke actions · hunting DSΣPDDCSCW [LLM] Cloud instance-metadata (IMDS 169.254.169.254) credential theft by interpreter/shell in pipeline pod Bespoke actions · alerting DSΣDDCS [LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) Bespoke c2 · hunting DSΣPCS [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] Cloud IMDS credential harvesting by node/npm/bun during package install (Sha1-Hulud/Megalodon) Bespoke actions · hunting DSΣPDDCS [LLM] CI/dev host exfiltrating to api.github.com shortly after cloud IMDS harvest (Sha1-Hulud exfil chain) Bespoke actions · hunting DSPCS [LLM] Cloud instance-metadata harvesting from npm/node install context (Miasma credential theft) Bespoke actions · alerting DSPCS [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) Bespoke actions · hunting DSPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Package-manager process harvesting cloud metadata / Vault (IMDS 169.254.169.254, ECS 169.254.170.2, Vault :8200) Bespoke actions · hunting DSPDDCS [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Cloud metadata service (IMDS) access from npm / node child process Bespoke actions · alerting DSPDDCS [LLM] Web-app runtime egress to AWS IMDS endpoint (169.254.169.254) — SSRF credential theft Bespoke actions · hunting DSΣPDDCS [LLM] SSRF probe via 'instance-data' IMDS alias hostname resolution Bespoke actions · hunting DSΣPDDCS [LLM] EC2 instance IMDS credential theft via curl/wget to security-credentials path Bespoke exploit · hunting DSΣPDDCS [LLM] WAF-Role EC2 instance credentials used from external IP (instance credential exfiltration) Bespoke actions · alerting PDDCW

Articles citing this technique (16)