The initiation or activation of a virtual machine instance within a cloud infrastructure. This action typically involves starting an existing instance that had been stopped or paused, allowing it to resume operation. Examples:
instance.start API activity.StartInstances in AWS CloudTrail for EC2 instances.Microsoft.Compute/virtualMachines/start entries indicate a VM instance being started.Data Collection Measures:
| Name | Channel |
|---|---|
| AWS:CloudTrail | StartInstances |
| AWS:CloudTrail | StartInstances: Instance starts from suspicious AMI or with userData present |
| AWS:CloudTrail | RunInstances |
| CloudTrail:EC2 | RunInstances |
| CloudTrail:RunInstances | RunInstances |
| CloudTrail:RunInstances | RunInstances: AMI not in allowlist OR AMI owner != enterprise owner/account |