Modify Cloud Compute Infrastructure: Create Cloud Instance

Threat Actors may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new instance may allow Threat Actors to bypass firewall rules and permissions that exist on instances currently residing within an account. Threat Actors may Create Snapshotof one or more volumes in an account, create a new instance, mount the snapshots, and then apply a less restrictive security policy to collect Data from Local System or for Remote Data Staging.

ID: ATAGS-T1101.001
Sub-technique of:  ATAGS-T1101
Tactic: Defense Evasion
Targeted Components: Cloud Control Plane
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.