{"id":"T1648","name":"Serverless Execution","url":"https://attack.mitre.org/techniques/T1648","tactics":["execution"],"platforms":["SaaS","IaaS","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0374","stix_id":"x-mitre-detection-strategy--7a848f8f-4bdc-426c-989e-bc1abfaeb7fa","name":"Detection Strategy for Serverless Execution (T1648)","url":"https://attack.mitre.org/detectionstrategies/DET0374","analytics":[{"id":"AN1053","stix_id":"x-mitre-analytic--ecf190d1-5311-466f-a361-a33820b3c7b7","name":"Analytic 1053","description":"Correlate creation or modification of serverless functions (e.g., AWS Lambda, GCP Cloud Functions, Azure Functions) with anomalous IAM role assignments or permissions escalation events. Detect subsequent executions of newly created functions that perform unexpected actions such as spawning outbound network connections, accessing sensitive resources, or creating additional credentials.","url":"https://attack.mitre.org/detectionstrategies/DET0374#AN1053","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"CreateFunction / UpdateFunctionConfiguration: Function creation, role assignment, or configuration change events","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"InvokeFunction: Unexpected or repeated invocation of functions not tied to known workflows","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"RoleScope","description":"Which IAM roles or privileges are considered sensitive when applied to functions"},{"field":"AllowedFunctions","description":"Known baseline list of approved serverless functions to reduce false positives"},{"field":"TimeWindow","description":"Temporal threshold for correlating function creation with anomalous execution"}],"live":true,"detection_strategies":["DET0374"],"techniques":["T1648"]},{"id":"AN1054","stix_id":"x-mitre-analytic--f8787a86-552b-4e03-8d68-7177001a215d","name":"Analytic 1054","description":"Monitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0374#AN1054","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"AddFlow / UpdateFlow: New automation or workflow creation events","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"m365-unified"},{"name":"m365:exchange","channel":"New-InboxRule: Automation that triggers abnormal forwarding or external link generation","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-exchange"}],"mutable_elements":[{"field":"UserContext","description":"Business units or users where automation creation is expected (developers, admins)"},{"field":"FlowActions","description":"Specific automation actions (email forwarding, file sharing) that should be considered suspicious"}],"live":true,"detection_strategies":["DET0374"],"techniques":["T1648"]},{"id":"AN1055","stix_id":"x-mitre-analytic--8708dc0b-8eeb-4a3d-8770-2fab30f46682","name":"Analytic 1055","description":"Track creation or update of SaaS automation scripts (e.g., Google Workspace Apps Script). Detect when these scripts are bound to user events such as file opens or account modifications, and correlate with subsequent abnormal API calls that exfiltrate or modify user data.","url":"https://attack.mitre.org/detectionstrategies/DET0374#AN1055","platforms":["SaaS"],"log_source_references":[{"name":"saas:appsscript","channel":"Create / Update: Deployment of scripts with event-driven triggers","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"saas-appsscript"},{"name":"saas:googledrive","channel":"FileOpen / FileAccess: Event-driven script triggering on user file actions","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-googledrive"}],"mutable_elements":[{"field":"ScriptScope","description":"Which SaaS apps or APIs can be legitimately automated in the environment"},{"field":"TriggerTypes","description":"Event-driven triggers (e.g., on file open, on user creation) considered suspicious"}],"live":true,"detection_strategies":["DET0374"],"techniques":["T1648"]}],"live":true,"version":"1.0","techniques":["T1648"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}