Changes made to a virtual machine (VM) or compute instance, including alterations to its configuration, metadata, attached policies, or operational state. Such modifications can include updating metadata, attaching or detaching resource policies, resizing instances, or modifying network configurations. Examples:
ModifyInstanceAttribute, ModifyInstanceMetadataOptions, or RebootInstances.Microsoft.Compute/virtualMachines/write.instances.setMetadata, instances.addResourcePolicies, or instances.resize.Data Collection Measures:
| Name | Channel |
|---|---|
| AWS:CloudTrail | RevertSnapshot |
| azure:activity | MICROSOFT.COMPUTE/VIRTUALMACHINES/RESTORE |
| gcp:audit | compute.instances.restore |
| ID | Name | Technique Detected |
|---|---|---|
| DET0337 | Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance | T1578.004 |