Instance Creation

The initial provisioning and construction of a virtual machine (VM) or compute instance within a cloud infrastructure environment. This activity involves defining and allocating resources such as CPU, memory, storage, and networking to spin up a new compute instance. Examples:

  • AWS: creating an EC2 instance using RunInstances API calls.
  • Azure, creating a VM through the Azure Resource Manager (ARM).
  • GCP, an instance.insert action recorded.
ID: DC0076
Domains: Enterprise
Version: 2.0
Created: 20 October 2021
Last Modified: 12 November 2025

Log Sources

Name Channel
AWS:CloudTrail RunInstances,CreateImage
azure:activity Microsoft.Compute/virtualMachines/write: imageReference publisher NOT IN allowlist OR plan is new/unknown
azure:activity MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE
gcp:audit compute.instances.insert: sourceImage not in approved projects OR has external image link
gcp:audit compute.instances.insert

Detection Strategy