LiveActive security incident?Get immediate response
MITRE ATT&CK® Detection Strategy

DET0492: Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations

MITRE ATT&CK DET0492: Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations Detection Strategy details, with detection…

EnterpriseDET0492Detection StrategyObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

DET0492 is a MITRE ATT&CK detection strategy object for detecting modifications to cloud compute configurations associated with T1578.005. The business significance is that changes to quotas, subscription associations, tenant-wide policies, or other compute-resource settings can weaken defensive visibility or enable misuse of cloud capacity without necessarily disrupting running workloads. Leaders should treat this as a cloud governance and resilience validation area, not only a SOC alerting problem.

Executive priority

Prioritize this where IaaS environments support critical services or material cloud spend. The key management question is whether the organization can prove who changed cloud compute capacity or policy settings, whether those changes were authorized, and whether abnormal changes would trigger timely investigation. This supports incident decision-making, audit evidence, cloud cost/risk governance, and defense-impairment readiness.

Technical view

The supplied ATT&CK object has no official detection text and no platform listed on the detection strategy itself. Its relationship detects T1578.005, which is an enterprise ATT&CK technique under defense-impairment on IaaS. SOC and detection teams should validate monitoring for control-plane changes that affect cloud compute size, location, resource availability, service quotas, subscription associations, and tenant-wide policies. IR teams should be able to reconstruct the actor identity, source context, affected scope, before/after configuration state, and whether the change was approved.

Likely telemetry

  • Cloud control-plane audit logs for compute and account/subscription/tenant configuration changes
  • IAM authentication and authorization logs tied to the principal making the change
  • Configuration history or cloud asset inventory showing before/after state
  • Service quota, policy, subscription association, and resource availability change records
  • Change-management tickets, approvals, and administrator activity records for false-positive reduction

Detection direction

  • Baseline expected administrative changes to cloud compute configuration and alert on changes outside approved change windows or by unusual principals.
  • Correlate configuration-change events with IAM context, source location, role/session information, and change-management evidence.
  • Prioritize detections around settings that affect available compute resources, tenant-wide policies, service quotas, or subscription associations because the related technique is categorized as defense impairment.
  • Tune for legitimate cloud operations such as capacity planning, migration, or policy administration to avoid excessive false positives.
  • Check blind spots where cloud audit logging, configuration history, or centralized log retention is incomplete across IaaS accounts, subscriptions, tenants, or regions.

Mitigation priorities

  • Establish least-privilege administration for cloud compute configuration, quota, subscription, and tenant-wide policy changes.
  • Require documented approval and review for material compute configuration changes, especially those affecting capacity, location, or policy scope.
  • Ensure cloud control-plane audit logs and configuration history are enabled, centralized, retained, and accessible to SOC and IR teams.
  • Use periodic governance review to compare current compute configuration against expected baselines.
  • Prepare incident response playbooks for unauthorized cloud configuration changes, including rollback decision points and identity containment.
Additional notes and limits

This take is based on the detection strategy object DET0492 and its relationship to T1578.005 Modify Cloud Compute Configurations. The detection strategy object itself does not provide an official description or detection logic, so the practical guidance is derived from the related technique description and its stated IaaS and defense-impairment context.

No active exploitation, actor attribution, vendor-specific platform detail, or guaranteed detection coverage is stated in the supplied ATT&CK fields. Local cloud architecture, logging configuration, IAM model, and change-management process are required to determine actual coverage and risk.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

1 rows
DomainIDNameRelationship / procedure
EnterpriseT1578.005Modify Cloud Compute ConfigurationsSub-techniqueThis object detects Modify Cloud Compute Configurations.
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
c3216d937d268f6b...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlec3216d937d26…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    mitre-attackDET0492
    Open source URL
  2. [2]
    mitre-attackDET0492
    Open source URL
  3. [3]
    mitre-attackDET0492
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.