SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Cloud Service Discovery

Cloud service discovery is like a burglar who, after breaking into a house, starts looking around to see what kind of smart home devices, security systems, or specialized tools are installed so they can figure out how to best exploit them.

Cloud service discovery is the process where an adversary, having gained initial access to a cloud environment, probes APIs and management interfaces to identify active services—such as CI/CD pipelines, AI inference endpoints, or security logging tools—to map the attack surface and determine which resources can be leveraged for further exploitation.

Cloud service discovery is a post-compromise reconnaissance technique wherein an adversary utilizes native cloud APIs (e.g., Microsoft Graph, Azure Resource Manager, AWS CLI) to enumerate the configuration, identity permissions, and service topology of an environment. This includes identifying PaaS, IaaS, SaaS, and AIaaS components, specifically targeting AI model endpoints, logging services, and security controls to facilitate lateral movement, privilege escalation, or unauthorized model inference.


← all terms