Cloud service metadata refers to the contextual and descriptive information about cloud services, including their name, type, purpose, configuration, and activity around them. This metadata is essential for understanding the roles and functions of cloud services, their operational status, and their potential misuse. Examples:
DescribeInstances API call.gcloud compute instances describe.This data component can be collected through the following measures:
Enable Cloud Metadata APIs
DescribeInstances, DescribeBuckets, etc.az resource list or SDKs.gcloud compute instances describe or related commands.Centralize Metadata in a Security Platform
Enable Continuous Monitoring
Configure Access and Logging
Use Cloud Security Tools
| Name | Channel |
|---|---|
| AWS:CloudTrail | rds:ExecuteStatement: Large data access via RDS or Aurora with unknown session context |
| AWS:CloudWatch | unexpected IAM user or role assuming privileges for instance/snapshot operations |
| CloudTrail:GetInstanceIdentityDocument | GetInstanceIdentityDocument |
| CloudTrail:GetSecretValue | API call to retrieve secret or access key |
| CloudTrail:InvokeFunction | InvokeFunction |
| m365:exchange | Cmdlet - New-InboxRule |
| m365:sharepoint | Multiple file download operations on a site by a privileged account in a short time window |
| m365:unified | New-InboxRule, Set-InboxRule |
| saas:github | repo.download, repo.clone, oauth.authorize, repo.getContent |
| saas:github | CI/CD secret accessed or exported |