The initial provisioning and construction of a virtual machine (VM) or compute instance within a cloud infrastructure environment. This activity involves defining and allocating resources such as CPU, memory, storage, and networking to spin up a new compute instance. Examples:
instance.insert action recorded.Data Collection Measures:
| Name | Channel |
|---|---|
| AWS:CloudTrail | RunInstances,CreateImage |
| azure:activity | Microsoft.Compute/virtualMachines/write: imageReference publisher NOT IN allowlist OR plan is new/unknown |
| azure:activity | MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE |
| gcp:audit | compute.instances.insert: sourceImage not in approved projects OR has external image link |
| gcp:audit | compute.instances.insert |