Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is command and control over a legitimate cloud service?

An offender can use cloud storage, messaging, webhooks, repositories or serverless services to publish tasks, retrieve configuration or receive results. Traffic to a familiar provider is therefore neither automatically benign nor proof of misuse.

Identify the exact cloud object

Preserve service, tenant, account, object or channel identifiers, API requests, authentication method, content, timestamps and source process. Broad provider traffic is weak evidence because legitimate and malicious operations share the same infrastructure.

Provider audit records can show creation, modification and access even after an object is deleted. Obtain account actions as well as content, subject to provider retention and lawful process.

Limit infrastructure attribution

A malicious process may use one object inside a provider the organisation otherwise relies upon. Do not attribute or block the entire service from that finding.

The cloud account may be false or compromised, and the provider is not implicated by carrying the traffic. Connect the precise API action to local tasking or data transfer, then assess who controlled the account separately.

Key takeaway

Resolve cloud command traffic to a specific account, object, API action and process; provider reputation alone establishes neither safety nor malicious control.

Reference: CIM-149Cyber Incidents & Offender Methods