ATK — Attacker mission
Turn a single foothold into account-wide control: abuse the instance metadata service, harvest credentials, walk IAM trust relationships, and reach the data store.
In the cloud, the perimeter is identity — and one over-permissioned role is all the foothold an attacker needs.
Turn a single foothold into account-wide control: abuse the instance metadata service, harvest credentials, walk IAM trust relationships, and reach the data store.
Enforce least privilege and zero-trust segmentation, detect anomalous API calls, cut the abused role, and keep the blast radius to one account.
How fast you spotted the metadata call, whether you scoped the over-permissioned role, and the lateral-movement path you did — and didn’t — see.
Technique IDs are indicative of the kill chains modelled in this domain; each match draws a unique path through them.
Attack. Defend. Repeat.