FORENSIA

ATT&CK · T1552.005 · sub-technique

Cloud Instance Metadata API

Tactics: credential-access

About

Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data. Most cloud service providers support a Cloud Instance Metadata API which is a service provided to running virtual instances that allows applications to access information about the running virtual instance. Available information generally includes name, security group, and additional metadata including sensitive data such as credentials and UserData scripts that may contain additional secrets. The Instance Metadata API is provided as a convenience to assist in managing applications and is accessible by anyone who can access the instance. A cloud metadata API has been used in at least one high profile compromise. If adversaries have a presence on the running virtual instance, they may query the Instance Metadata API directly to identify credentials that grant access to additional resources. Additionally, adversaries may exploit a Server-Side Request Forgery (SSRF) vulnerability in a public facing web proxy that allows them to gain access to the sensitive information via a request to the Instance Metadata API. The de facto standard across cloud service providers is to host the Instance Metadata API at <code>http[:]//169.254.169.254</code>.

Used by actors

1 known groups

Software

4 malware/tools implement this

HildegardPeiratesShai-HuludTruffleHog

Corpus indicators tagged with this technique

6 indicators in the corpus carry T1552.005.

IndicatorTypeFamilySevSrc
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801
18821dbb53892d6faa14b1f063517a0302057290hashcryptojacking801
cf127d66124c390ca0f0b42c6385c3c8hashcryptojacking801
d0a851f0b871df60c73d2c7d3f55b031c45e4c2ehashcryptojacking801
d75cb9920d1d3d280518ddccfe4789d2hashcryptojacking801
e22d1b625ee309b60caf0252c5df7656hashcryptojacking801