Compliance Node Overview
MITRE ATT&CK T1578.003 (Delete Cloud Instance) is an Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence. Deleting an instance or virtual machine can remove valuable forensic artifacts and other evidence of suspicious behavior if the instance is not recoverable. An adversary may also Create Cloud Instance and later terminate the instance after achieving their objectives. Affected platforms: IaaS. MITRE-documented mitigations include M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-02, CM-05, IA-02, IA-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1578/003/
SHA-256 integrity: f8a63f6ccbf91602675d03935a3e9f08dd8b03bfd2994a712f4a0a2da39b5114
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1578.003: Delete Cloud Instance (https://attack.mitre.org/techniques/T1578/003/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.