Modify Cloud Compute Infrastructure: Revert Cloud Instance

Threat Actors may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence. In highly virtualized environments, such as cloud-based infrastructure, this may be accomplished by restoring virtual machine (VM) or data storage snapshots through the cloud management dashboard or cloud APIs.

ID: ATAGS-T1101.005
Sub-technique of:  ATAGS-T1101
Tactic: Defense Evasion
Targeted Components: Cloud Control Plane
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.