What MITRE ATT&CK T1651: Cloud Administration Command (Enterprise Tactic TA0002 - Execution) requires
MITRE ATT&CK T1651 (Cloud Administration Command) is an Enterprise Execution technique. Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents. If an adversary gains administrative access to a cloud environment, they may be able to abuse cloud management services to execute commands in the environment's virtual machines. Affected platforms: IaaS. MITRE-documented mitigations include M1026 Privileged Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, AC-17, IA-02, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1651/
SHA-256 integrity: ed166b59567ae849c2af58435ec31cc17ecf91ca5503a86c9e3e9937e18f52fe
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1651: Cloud Administration Command (https://attack.mitre.org/techniques/T1651/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1651-cloud-administration-command.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1651-cloud-administration-command.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1651-cloud-administration-command
- Back to registry: Browse all 10,085 compliance nodes