WithSecure Repository: Vulnerabilities & Tactics, Techniques and Procedures

Cloud Asset Destruction

This class is an extension of the MITRE ATT&CK matrix and represents an adversary destroying cloud assets. It is related to (but to be considered distinct from) data destruction.

An adversary with control plane delete access could destroy cloud assets, such as virtual machines, storage accounts, serverless functions and databases. If the adversary is also able to destroy backups or older versions of data, the damage they cause may be irreparable.

Mitigations: Limit control plane access to only a few users who actually need it. Consider using Just-In-Time access mechanisms, rather than permanent role/policy assignments. Backup data at intervals and store it in a separate account.

ID: WITH-6
Domain: withsecure-attack-extension
Version: 1.0