{"id":"T1535","name":"Unused/Unsupported Cloud Regions","url":"https://attack.mitre.org/techniques/T1535","tactics":["stealth"],"platforms":["IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0247","stix_id":"x-mitre-detection-strategy--ec3e5f66-a2b8-48ae-9adf-eb4f5014ba70","name":"Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)","url":"https://attack.mitre.org/detectionstrategies/DET0247","analytics":[{"id":"AN0690","stix_id":"x-mitre-analytic--5d4419cc-6925-4f7d-a247-e0a4634fea90","name":"Analytic 0690","description":"Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).","url":"https://attack.mitre.org/detectionstrategies/DET0247#AN0690","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"RunInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"CreateBucket","data_component":"DC0024","data_component_name":"Cloud Storage Creation","log_source_slug":"aws-cloudtrail"},{"name":"CloudTrail:GetCallerIdentity","channel":"GetCallerIdentity","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"cloudtrail-getcalleridentity"},{"name":"AWS:VPCFlowLogs","channel":"High outbound traffic from new region resource","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"aws-vpcflowlogs"}],"mutable_elements":[{"field":"UnusedRegionList","description":"List of regions historically unused by the organization (can vary per tenant/project)"},{"field":"TimeWindow","description":"Time interval for correlating activity following account access"},{"field":"AllowedServiceList","description":"Whitelist of services allowed in secondary/DR regions"},{"field":"OutboundTrafficThreshold","description":"Volume threshold to flag suspicious outbound activity"}],"live":true,"detection_strategies":["DET0247"],"techniques":["T1535"]}],"live":true,"version":"1.0","techniques":["T1535"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}