Tracking cloud-fluent threat actors - Part one: Atomic cloud IOCs
ID: 8bb4482f-9ad4-59d0-a9db-1fe7919e31c3
STIX ID: report--8bb4482f-9ad4-59d0-a9db-1fe7919e31c3
Feed Name: Wiz Blog
This report explains how to identify and operationalize cloud-specific atomic IOCs—such as container/VM image metadata, cloud subscription IDs, IaC artifacts, IAM user/credential naming patterns, user-agent strings, and IP addresses—to detect and investigate cloud attacks. It highlights real-world examples (e.g., TeamTNT images, DangerDev AWS accounts 671050157472 and 265857590823, AndroxGh0st-created IAM users, and IP 134.209.127.249) and maps techniques to MITRE ATT&CK. The article concludes with practical guidance for integrating these IOCs into cloud inventories and log-based detections, and references a public GitHub repository aggregating known atomic cloud IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
