[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/cloud-virtual-machine-attack-vectors/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/cloud-virtual-machine-attack-vectors/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/ "Cloud Cybersecurity Research")  
  [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/)

# Attack Paths Into VMs in the Cloud

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex Xpanse icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex Xpanse](https://unit42.paloaltonetworks.com/product-category/cortex-xpanse/ "Cortex Xpanse")[![Prisma Cloud icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/prisma_RGB_logo_Icon_Color.png)Prisma Cloud](https://unit42.paloaltonetworks.com/product-category/prisma-cloud/ "Prisma Cloud")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Jay Chen](https://unit42.paloaltonetworks.com/author/jay-chen/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 18, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cloud Cybersecurity Research](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [AWS](https://unit42.paloaltonetworks.com/tag/aws/)
  * [Azure](https://unit42.paloaltonetworks.com/tag/azure/)
  * [IaaS](https://unit42.paloaltonetworks.com/tag/iaas/)
  * [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/)
  * [Virtual machines](https://unit42.paloaltonetworks.com/tag/virtual-machines/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/cloud-virtual-machine-attack-vectors/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/cloud-virtual-machine-attack-vectors/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Attack%20Paths%20Into%20VMs%20in%20the%20Cloud&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcloud-virtual-machine-attack-vectors%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcloud-virtual-machine-attack-vectors%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcloud-virtual-machine-attack-vectors%2F&title=Attack%20Paths%20Into%20VMs%20in%20the%20Cloud "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcloud-virtual-machine-attack-vectors%2F&text=Attack%20Paths%20Into%20VMs%20in%20the%20Cloud "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcloud-virtual-machine-attack-vectors%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Attack%20Paths%20Into%20VMs%20in%20the%20Cloud%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcloud-virtual-machine-attack-vectors%2F "Share in Mastodon")

## **Executive Summary**

This post reviews strategies for identifying and mitigating potential attack vectors against virtual machine (VM) services in the cloud. Organizations can use this information to understand the potential risks associated with their VM services and strengthen their defense mechanisms. This research focuses on VM services offered by three major cloud service providers (CSPs): Amazon Web Services (AWS), Azure and Google Cloud Platform (GCP).

VMs are among the most frequently deployed resources in every cloud environment. Their widespread use also makes them a prime target for attackers. Our research shows that [11% of cloud hosts exposed to the internet contain vulnerabilities](https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research) rated Critical or High severity.

A compromised VM can provide attackers with access to not only the data within the VM instance but also the permissions assigned to it. As compute workloads like VMs are generally ephemeral and immutable, the risk posed by a compromised identity is arguably greater than that of compromised data within a VM.

It is important to note that all the attack paths discussed in this post are intended features with legitimate use cases, such as streamlining the configuration, updating, and monitoring of VMs across hybrid or multi-cloud environments, rather than vulnerabilities. However, if security best practices are not followed, accounts are not protected, and careful attention isn't given to the design of your architecture, malicious users could misuse these services or features. The responsibility of protecting and mitigating these attack paths falls on the cloud users and administrators.

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Prisma Cloud](https://docs.paloaltonetworks.com/prisma/prisma-cloud) customers are better protected by the [attack path policies](https://docs.prismacloud.io/en/classic/cspm-admin-guide/prisma-cloud-policies/attack-path-policies) continuously monitoring and alerting on potential attack paths.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response) detects and blocks exploits and evasive cloud-based attacks.
* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) can detect shadow IT running in public cloud providers and help bring these resources under management.
* The [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk.

| **Related Unit 42 Topics** | [**Cloud Cybersecurity Research**](https://unit42.paloaltonetworks.com/category/cloud-cybersecurity-research/) |
|----------------------------|----------------------------------------------------------------------------------------------------------------|

## **Summary of the VM Attack Paths**

We explore the conditions and permissions for each attack path into a running VM instance to assist organizations in fine-tuning their detection and mitigation mechanisms. Table 1 provides an overview of all the attack paths we discuss.

|---------------------------------|--------------------------------------------------------------------|------------------------------------------------------------------------------------|------------------------------------------------------------------------|
|                                 | **AWS**                                                            | **Azure**                                                                          | **GCP**                                                                |
| **Vulnerability Exploitation**  | Feasible: Yes  Complexity: Depends                           | Feasible: Yes  Complexity: Depends                                           | Feasible: Yes  Complexity: Depends                               |
| **Startup Script Manipulation** | Feasible: Yes  Feature: EC2 User Data Complexity: Low        | Feasible: only VM Scale Sets  Feature: VM custom data Complexity: Low        | Feasible: Yes  Feature: Metadata Startup Scripts Complexity: Low |
| **SSH Key Push**                | Feasible: Yes  Feature: EC2 Instance Connect Complexity: Low | Feasible: Yes  Feature: VMAccess extension Complexity: Medium                | Feasible: Yes  Feature: Metadata, OSLogin Complexity: Low        |
| **Direct Code Execution**       | Feasible: Yes  Feature: SSM Run Command Complexity: Medium   | Feasible: Yes  Feature: Run Command, Custom Script Extension Complexity: Low | Feasible: Yes  Feature: VM Manager Complexity: Medium            |
| **SSH Over Middleware**         | Feasible: Yes  Feature: SSM Session Manager Complexity: Low  | Feasible: No                                                                       | Feasible: No                                                           |
| **Serial Console Access**       | Feasible: Yes  Feature: EC2 Serial Console Complexity: High  | Feasible: Yes  Feature: Azure Serial Console Complexity: High                | Feasible: Yes  Feature: Metadata/Serial Console Complexity: Low  |

*Table 1. Summary of VM attack paths.*

## **Understanding VMs in the Cloud**

VMs are among the oldest and most widely used infrastructure-as-a-service (IaaS) offerings across all cloud service providers. They offer a swift and straightforward method to "lift and shift" on-premises applications to the cloud, maintaining the same user experience at the operating system level and above. Modern VM services support a broad spectrum of operating systems, from Linux to Windows to macOS, enabling virtually any application to be deployed in the cloud.

While VMs might not be the most novel cloud technology today, they continue to host many vital cloud workloads. If a VM is compromised, attackers can not only exfiltrate sensitive data and hijack computational resources but also gain access to all the cloud permissions granted to the VM.

As the tactics, techniques and procedures (TTPs) employed by attackers in the cloud largely depend on the permissions they have managed to obtain, one common method of gaining more permissions is to compromise a compute resource, such as a VM, and hijack its workload identity. As a result, each VM instance can potentially serve as a stepping stone towards an attacker's goal, making it crucial to meticulously manage the VM's attack surface.

We define a VM attack path as a series of steps and conditions that could potentially allow an attacker to log in or execute commands in a VM instance. We assume that attackers possess basic information about the targeted VM, such as its unique identifier (UID), IP address, virtual private cloud (VPC) and region.

This information, which is not typically considered confidential, can be sourced from logs, code, or low-privileged read permissions. However, attackers do not possess the login credentials for VMs. The majority of the attack paths discussed in this post rely on [control plane](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/control-plane-and-data-plane#control-plane) application programming interfaces (APIs) to gain access to a VM.

Subsequent sections will each cover a specific technique and explore the attack paths related to that technique in each CSP. We will outline the preconditions for each attack path, noting that while these conditions are necessary, they might not be sufficient. For instance, to exploit these attack paths, we assume the attackers have obtained the required permissions through means such as credential leaks or phishing in order to exploit a specific attack path.

We will focus on the most relevant permissions or configurations that result in these attack paths. Although most of the techniques described are not specific to any particular VM operating system, for simplicity, the references and examples provided will primarily be based on Linux systems.

## **Vulnerability Exploitation**

Our research reveals that [11% of the cloud hosts exposed to the internet contain Critical or High severity vulnerabilities](https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research). Exploiting these vulnerabilities is one of the most common ways attackers use to [gain initial access](https://unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/) to cloud environments.

Given that modern applications are bundled with hundreds of dependent packages, the emergence of new vulnerabilities is accelerating faster than ever. Regardless of the instance type and cloud type, if attackers can identify a remotely exploitable vulnerability exposed by a VM, they could potentially compromise and take control of it.

**Conditions**:

* The target VM has a vulnerability exposed to the network that can be exploited remotely.
* The vulnerability allows remote code execution, file access or file overwriting.

**Mitigations**:

* Enable vulnerability scanning services, such as [Prisma Cloud Vulnerability Management](https://www.paloaltonetworks.com/prisma/cloud/vulnerability-management), [Amazon Inspector](https://aws.amazon.com/inspector/), [Microsoft Defender for Cloud](https://azure.microsoft.com/en-us/products/defender-for-cloud) and [Google Security Command Center](https://cloud.google.com/security/products/security-command-center?hl=en)

## **Startup Script Manipulation**

A startup script is a file that executes tasks during the initialization process of a VM instance. These scripts are typically used to set up the environment, download dependencies, initialize services and fetch updates. If attackers gain permissions to alter a VM's startup script, they could exploit this feature to inject malicious code into the VMs.

### AWS: Modify Startup Scripts in User Data

When launching a new EC2 instance, users can optionally pass parameters or scripts in [user data](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instancedata-add-user-data.html). Any scripts in user data are run when the instance is launched. By default, the scripts are only executed during the first boot of the instance. However, it is possible to configure the cloud-init directives to [force scripts to execute at every restart](https://repost.aws/knowledge-center/execute-user-data-ec2).

**Conditions**:

* The Amazon Machine Images (AMI) used for creating EC2 VM must support the user data and cloud-init functionality.
* The principals have the following permissions to alter a VM's user data and restart the VM:
  * ec2:StopInstances
  * ec2:ModifyInstanceAttribute
  * ec2:StartInstances

**Mitigations**:

* Restrict and monitor the use of the ec2:ModifyInstanceAttribute permission.

### Azure: Modify Startup Scripts in Custom Data

The startup scripts are stored and passed to an Azure VM via its [custom data](https://learn.microsoft.com/en-us/azure/virtual-machines/custom-data). For a single VM, its custom data can only be set once at boot time and can't be updated subsequently. However, custom data of a VM Scale Set, a group of VMs, can be [updated](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-upgrade-scale-set#how-to-update-global-scale-set-properties).

Newly initiated VMs will receive the updated custom data. Existing VMs, on the other hand, need to be [reimaged](https://learn.microsoft.com/en-us/powershell/module/az.compute/invoke-azvmreimage?view=azps-11.3.0) to receive the new custom data.

**Conditions**:

* The principals have the following permissions to [update](https://learn.microsoft.com/en-us/powershell/module/az.compute/update-azvmss?view=azps-11.3.0) the state of a VM scale set and reimage a VM.
  * Microsoft.Compute/virtualMachineScaleSets/write

**Mitigations**:

* Restrict and monitor the use of the Microsoft.Compute/virtualMachineScaleSets/write permission.

### GCP: Modify Startup Scripts in Metadata

Compute Engine's [metadata service](https://cloud.google.com/compute/docs/metadata/overview) offers a mechanism for storing and retrieving metadata in the form of key-value pairs, including startup/shutdown scripts, SSH keys and numerous [feature flags](https://cloud.google.com/compute/docs/metadata/predefined-metadata-keys). Metadata can be set at instance-level for each individual VM or project-wide level for all VMs within the project. Each VM is then configured according to its respective metadata.

The [startup-script](https://cloud.google.com/compute/docs/instances/startup-scripts/linux#metadata-keys) metadata key contains the commands that run when a VM instance boots.

**Conditions**:

* The [guest agent](https://cloud.google.com/compute/docs/images/guest-environment) is installed and activated.
* The principals have the following permissions to update a VM's metadata:
  * compute.instances.setMetadata (via VM's [instance metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-instance-metadata))
  * compute.projects.setCommonInstanceMetadata (via [project-wide metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-project-wide-metadata))
* The principals have the following permissions to [restart or reboot a VM](https://cloud.google.com/compute/docs/instances/stop-start-instance):
  * compute.instances.stop
  * compute.instances.start
  * compute.instances.reset

**Mitigations**:

* Restrict and monitor the use of the compute.instances.setMetadata and compute.projects.setCommonInstanceMetadata permissions.
* It is recommended to store startup scripts in cloud storage rather than metadata directly and using the [startup-script-url metadata key](https://cloud.google.com/compute/docs/instances/startup-scripts/linux) to point to it. This better secures potentially sensitive information in the startup script through change control and additional access controls as well as allows for a script greater than 256 KB in size.

## **SSH Key Push**

Given that each organization typically hosts various applications on hundreds (if not thousands) of VM instances in their cloud environments, managing the SSH keys for all these VMs can be a daunting task. To help streamline the process of credential management and access control, most CSPs offer features that allow for the easy insertion of SSH public keys into running VMs.

This process usually involves an agent running within a VM, fetching a public key from a cloud API endpoint, modifying the SSH daemon [(sshd) configuration file](https://linux.die.net/man/5/sshd_config) and overwriting the [authorized\_keys](https://linux.die.net/man/8/sshd) file on the VM. If attackers gain permissions to push SSH keys, they could [exploit this feature](https://unit42.paloaltonetworks.com/cloud-lateral-movement-techniques/) to gain unauthorized access to VMs.

### AWS: Use EC2 Instance Connect to Push SSH Keys

[EC2 Instance Connect](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connect-linux-inst-eic.html) provides a simple and secure method to manage SSH access to Linux VMs using identity and access management (IAM). When a user needs to SSH into a VM, Instance Connect pushes a temporary public key to the VM, allowing the user to authenticate with the SSH daemon.

**Conditions**:

* The [EC2 Instance Connect agent](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-set-up.html) is installed and activated. The VM itself doesn't require any permissions.
* The principals have the following [permission](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-configure-IAM-role.html#eic-permissions-allow-users-to-connect-to-specific-instances) to push SSH keys:
  * ec2-instance-connect:SendSSHPublicKey

**Mitigations**:

* Restrict and monitor the use of the ec2-instance-connect:SendSSHPublicKey permission.
* [Uninstall](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-uninstall.html) the EC2 Instance Connect if the feature is not needed.

### Azure: Use VMAccess Extension to Push SSH Keys

[VM Extensions](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/overview) are small applications that facilitate post-deployment configuration and automation on VM instances. These extensions offer functions such as system configuration, system monitoring and system backup.

The [VMAccess](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-linux) extension allows the management of administrative users on Linux VMs for tasks like setting a user's password, pushing an SSH public key or creating a new sudo user. The [az vm user](https://learn.microsoft.com/en-us/cli/azure/vm/user?view=azure-cli-latest) command relies on the VMAccess extension to manage user accounts in a VM.

**Conditions**:

* The Azure [VM agent](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux) is installed and activated.
* The principals have the following permission to [install](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/extensions-rmpolicy-howto-cli) an extension and [update](https://learn.microsoft.com/en-us/cli/azure/vm/user?view=azure-cli-latest) user accounts:
  * Microsoft.Compute/virtualMachines/extensions/write
  * Microsoft.Compute/virtualMachines/write

**Mitigations**:

* Restrict and monitor the use of the Microsoft.Compute/virtualMachines/extensions/write and Microsoft.Compute/virtualMachines/write permissions.
* Restrict the [type](https://learn.microsoft.com/en-us/azure/templates/microsoft.compute/virtualmachines/extensions?pivots=deployment-language-bicep) of extension that can be installed on VMs.
* Remove the VMAccess extension if it is not needed.

### GCP: Update Metadata to Push SSH Keys

Compute Engine's [metadata service](https://cloud.google.com/compute/docs/metadata/overview) offers a mechanism for storing and retrieving metadata in the form of key-value pairs. By updating the [SSH keys](https://cloud.google.com/compute/docs/connect/add-ssh-keys#metadata) metadata key, one can add SSH public keys to a VM instance.

**Conditions**:

* The [guest agent](https://cloud.google.com/compute/docs/images/guest-environment) is installed and activated.
* The principals have the following permission to update a VM's metadata:
  * compute.instances.setMetadata (via VM's [instance metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-instance-metadata))
  * compute.projects.setCommonInstanceMetadata (via [project-wide metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-project-wide-metadata))
  * iam.serviceAccounts.actAs (on the project level)

**Mitigations**:

* Restrict and monitor the use of the compute.instances.setMetadata and compute.projects.setCommonInstanceMetadata permissions.
* [Block](https://cloud.google.com/compute/docs/connect/restrict-ssh-keys#block-keys) metadata-based SSH Keys at the project level.

### GCP: Use OSLogin to Push SSH Keys

[OSLogin](https://cloud.google.com/compute/docs/oslogin) automatically manages SSH keys in metadata and user accounts in VM instances using Google Cloud Identity (IAM) policies. This is the [recommended way](https://cloud.google.com/compute/docs/instances/access-overview#risks) to manage SSH keys in VMs.

OSLogin can be enabled by updating the [enable-oslogin](https://cloud.google.com/compute/docs/oslogin/set-up-oslogin#enable_os_login_for_all_vms_in_a_project) metadata key in the metadata service. It is important to note that metadata-based SSH keys and OSLogin are two mutually exclusive features that can't both be enabled.

**Conditions**:

* [OSLogin agent](https://cloud.google.com/compute/docs/manage-os#check-install) is activated.
* The principals have the following permissions to update a VM's metadata:
  * compute.instances.setMetadata (via VM's [instance metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-instance-metadata))
  * compute.projects.setCommonInstanceMetadata (via [project-wide metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-project-wide-metadata))
  * iam.serviceAccounts.actAs (on the project level)
* The principals are associated with the [compute.osLogin](https://cloud.google.com/compute/docs/access/iam#compute.osLogin) role to connect to VMs using OSLogin.
* The principals, if outside of the organization, have the following [permission](https://cloud.google.com/compute/docs/access/iam#compute.osLoginExternalUser)
  * compute.oslogin.updateExternalUser

**Mitigations**:

* Restrict and monitor the use of the compute.instances.osLogin and compute.oslogin.updateExternalUser permissions.
* Enforce [OS Login with 2FA](https://cloud.google.com/compute/docs/oslogin/set-up-oslogin) at the project level.
* Enforce physical [security keys](https://cloud.google.com/compute/docs/oslogin/security-keys) for operating system (OS) Login at the project level.

## **Direct Code Execution**

To streamline the management and configurations of a fleet of VM instances, most CSPs offer features that allow the execution of commands or scripts across a set of VMs. This eliminates the need for VMs to have exposed management ports, [bastion hosts](https://cloud.google.com/solutions/connecting-securely#bastion) or even an active sshd running, increasing their security and cost-effectiveness.

These features usually rely on agents running in the VMs that fetch and execute commands from the cloud API endpoints. If attackers gain the necessary permissions to perform these actions, they could exploit these features to execute malicious code within the VMs.

### AWS: Use SSM Run Command to Execute Code

The [SSM Run Command](https://docs.aws.amazon.com/systems-manager/latest/userguide/run-command.html) allows users to execute commands on nodes where the System Manager is installed. The feature offers an easy way for performing one-time configurations or status checks across nodes in single-cloud, multi-cloud or hybrid cloud environments.

**Conditions**:

* The [SSM agent](https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-manual-agent-install.html) is installed and activated.
* The VM has the permissions specified in the [AmazonSSMManagedInstanceCore](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonSSMManagedInstanceCore.html) policy.
* The principals have the following permission
  * ssm:SendCommand

**Mitigations**:

* Restrict and monitor the use of the ssm:SendCommand permission.
* Restrict the [SSM documents](https://docs.aws.amazon.com/systems-manager/latest/userguide/security_iam_id-based-policy-examples.html#customer-managed-policies) that Run Command can execute.
* Revoke [SSM permissions](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonSSMManagedInstanceCore.html) from VMs that are not managed by SSM.
* Deactivate the [Default Host Management Configuration](https://docs.aws.amazon.com/systems-manager/latest/userguide/managed-instances-default-host-management.html#managed-instances-default-host-management-console) if it is not needed. This feature allows AWS System Manager to manage all the qualified EC2 instances.

### Azure: Use Virtual Machine Run Command to Execute Code

The [Run Command](https://learn.microsoft.com/en-us/azure/virtual-machines/run-command-overview) feature in Azure uses the VM agent within a VM to execute scripts. It can be used for application management, system diagnostics or troubleshooting when RDP or SSH service are unavailable.

**Conditions**:

* The Azure [VM agent](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux) is installed and activated.
* The principals have the following [permission](https://learn.microsoft.com/en-us/azure/virtual-machines/windows/run-command#limiting-access-to-run-command) to perform the Run Command
  * Microsoft.Compute/virtualMachines/runCommands/write

**Mitigations**:

* Restrict and monitor the use of the Microsoft.Compute/virtualMachines/runCommands/write permission.

### Azure: Use a Custom Script Extension to Run Scripts

[VM Extensions](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/overview) are small applications that can perform post-deployment configuration and automation on VM instances. The [custom script](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/custom-script-linux) extension allows for the downloading and execution of scripts within VMs.

**Conditions**:

* The Azure [VM agent](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux) is installed and activated.
* The principals have the following permission to [install](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/extensions-rmpolicy-howto-ps) an extension and [run](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/custom-script-linux#azure-cli) the custom script extension
  * Microsoft.Compute/virtualMachines/extensions/write
  * Microsoft.Compute/virtualMachines/write

**Mitigations**:

* Restrict and monitor the use of the Microsoft.Compute/virtualMachines/extensions/write and Microsoft.Compute/virtualMachines/write permissions.
* Restrict the [type](https://learn.microsoft.com/en-us/azure/templates/microsoft.compute/virtualmachines/extensions?pivots=deployment-language-bicep) of extension that can be installed.

### GCP: Use VM Manager to Execute Code

[VM Manager](https://cloud.google.com/compute/docs/vm-manager) is a suite of tools that can help manage a group of VMs. It is primarily used for applying patches, collecting OS information and installing or removing software packages.

#### Run Pre-Patch or Post-Patch Scripts

The [Patch](https://cloud.google.com/compute/docs/os-patch-management) feature can apply OS patches across a set of VM instances using OS package managers like the Advanced Packaging Tool ([APT](https://ubuntu.com/server/docs/package-management)) and Yellowdog Updater, Modified ([YUM](https://www.redhat.com/sysadmin/how-manage-packages)). During the creation of a patch job, optional [pre-patch or post-patch](https://cloud.google.com/compute/docs/os-patch-management/create-patch-job)scripts can be executed to either prepare for or test the patch.

#### Run Scripts in OS Policies

The [OS Policy](https://cloud.google.com/compute/docs/os-configuration-management/working-with-os-policies#example-2) feature allows users to maintain a consistent configuration in OSes across multiple VMs. Each policy file contains the declarative configuration for resources such as packages, repositories or files. One way to configure resources in an OS is [executing scripts](https://cloud.google.com/compute/docs/osconfig/rest/v1/projects.locations.osPolicyAssignments#execresource).

**Conditions**:

* The [guest agent](https://cloud.google.com/compute/docs/images/guest-environment) is installed and activated.
* OS Config is [enabled](https://cloud.google.com/compute/docs/manage-os#enable-metadata) in the metadata.
* The [OS Config agent](https://cloud.google.com/compute/docs/manage-os#agent-install) is installed and activated.
* The VM must have an [attached service account](https://cloud.google.com/compute/docs/manage-os#enable-metadata), although the service account doesn't need any permission.
* The principals need the following [permissions](https://cloud.google.com/compute/docs/os-patch-management/create-patch-job#permissions) to run a patch job:
  * osconfig.patchJobs.exec
  * osconfig.patchJobs.get
  * osconfig.patchJobs.list
* The principals need the following [permissions](https://cloud.google.com/compute/docs/os-configuration-management/create-os-policy-assignment#permissions) to manage OS policy assignments:
  * osconfig.osPolicyAssignments.update
  * osconfig.osPolicyAssignments.get
  * osconfig.osPolicyAssignments.list

**Mitigations**:

* Restrict and monitor the use of the osconfig.patchJobs.exec and osconfig.osPolicyAssignments.update permissions.
* Disable the Patch and OS policies feature by setting the [osconfig-disabled-features](https://cloud.google.com/compute/docs/manage-os#disable-features) metadata key at the project level.
* [Disable](https://cloud.google.com/compute/docs/manage-os#enable-metadata) OS Config in the metadata at the project level if it is not needed.
* [Uninstall the OS Config agent](https://cloud.google.com/compute/docs/manage-os#disable-agent) if it is not needed.

## **SSH Over Middleware**

### AWS: Use SSM Session Manager to Log into a VM

AWS [SSM Session Manager](https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html) provides a secure and auditable way to log into nodes using IAM. Nodes with Session Manager don't need to have open inbound ports and users logging into the nodes don't need to manage the private keys.

Session manager can also be configured on nodes in multi-cloud or hybrid cloud environments. If attackers gain permissions to perform the session manager's actions, they could potentially abuse the feature to log into VMs with the session manager running.

**Conditions**:

* The [SSM agent](https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-manual-agent-install.html) is installed and activated.
* The VM's instance profile has the following [permissions](https://docs.aws.amazon.com/systems-manager/latest/userguide/getting-started-add-permissions-to-existing-profile.html):
  * ssmmessages:CreateControlChannel
  * ssmmessages:CreateDataChannel
  * ssmmessages:OpenControlChannel
  * ssmmessages:OpenDataChannel
  * ssm:UpdateInstanceInformation
* The principals have the following [permissions](https://docs.aws.amazon.com/systems-manager/latest/userguide/getting-started-restrict-access-quickstart.html) to connect to the VM:
  * ssm:StartSession
  * ssm:ResumeSession
  * ssm:TerminateSession

**Mitigations**:

* Restrict and monitor the use of the ssm:StartSession and ssm:ResumeSession permissions.
* Revoke ssmmessages [permissions](https://docs.aws.amazon.com/systems-manager/latest/userguide/getting-started-add-permissions-to-existing-profile.html) from VMs that are not managed by the session manager.
* Deactivate [Default Host Management Configuration](https://docs.aws.amazon.com/systems-manager/latest/userguide/managed-instances-default-host-management.html#managed-instances-default-host-management-console) if it is not needed.
* [Uninstall](https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-uninstall-agent.html) the SSM agent if it is not needed.

## **Serial Console Access**

Most cloud service providers offer serial console access as a feature to troubleshoot boot and network configuration issues in VMs. This feature provides text-based console access to VMs, independent of the network and operating system state.

Because network-based access control does not apply to serial console access, attackers with serial console permissions could potentially [abuse this feature](https://unit42.paloaltonetworks.com/cloud-lateral-movement-techniques/) to bypass network-based firewall restrictions and gain unauthorized access to VMs. It is important to note that the serial console access does not bypass the user authentication. Valid passwords or private keys are still needed to log into a VM.

### AWS: Login via Serial Ports

[Amazon EC2 Serial Console](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connect-to-serial-console.html) provides access to the serial port of EC2 instances.

**Conditions**:

* Serial console access must be [enabled at the account level](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configure-access-to-serial-console.html#sc-grant-account-access).
* Principals with the ec2:EnableSerialConsoleAccess permission can enable access.
* The VM must be one of the [supported instance types](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.html#sc-prereqs-instance-types). Most instances built on the [Nitro System](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#nitro-instance-types) are supported.
  * Principals with the ec2:ModifyInstanceAttribute permission can change a VM's instance type.
* The principals must have a valid password or permission to push the SSH public key to the instance.
  * The principals with the ec2-instance-connect:SendSerialConsoleSSHPublicKey permission can push the SSH key into a VM via the serial console.

**Mitigations**:

* Disable serial console access at the account level.
* Restrict and monitor the use of ec2:EnableSerialConsoleAccess and ec2-instance-connect:SendSerialConsoleSSHPublicKey permissions.

### Azure: Login via Serial Ports

[Azure Serial Console](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-overview) provides text-based console access to VM instances.

**Conditions**:

* Serial Console is enabled at the [subscription level](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/serial-console-enable-disable#subscription-level-enabledisable). (It is enabled by default.)
* The VM's [boot diagnostic](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/boot-diagnostics) is enabled.
* The VM Guest OS has the [terminal management service](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/linux/serial-console-linux) enabled (e.g., getty in Linux and SAC in Windows). (They are enabled by default.)
* The VM Guest OS has text-based user authentication configured for local logins, (e.g., valid user/password).
* The principals have the following [permissions](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-enable-disable#enabling-least-privilege-access-to-serial-console-using-rbac) to connect to a VM via serial port:
  * Microsoft.Compute/virtualMachines/start/action
  * Microsoft.Compute/virtualMachines/read
  * Microsoft.Compute/virtualMachines/write
  * Microsoft.Resources/subscriptions/resourceGroups/read
  * Microsoft.Storage/storageAccounts/listKeys/action
  * Microsoft.Storage/storageAccounts/read
  * Microsoft.SerialConsole/serialPorts/connect/action

**Mitigations**:

* Restrict and monitor the use of the Microsoft.SerialConsole/serialPorts/connect/action permission.
* [Disable](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-enable-disable?source=recommendations) serial console access at the subscription level.
* Disable [boot diagnostic](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/boot-diagnostics) for individual VMs.
* Disable terminal management service for individual VMs.
* Disable text-based authentication for local logins, such as user/password for individual VMs.

### GCP: Login via Serial Ports

GCP provides an alternative way to connect to a VM over a serial port. Compute Engine serial port access can be [enabled](https://cloud.google.com/compute/docs/troubleshooting/troubleshooting-using-serial-console#enabling_interactive_access_on_the_serial_console) in the metadata service by updating the serial-port-enable metadata key.

**Conditions**:

* The [guest agent](https://cloud.google.com/compute/docs/images/guest-environment) is installed and activated on the VM.
* The principals have the following permissions to update a VM's metadata:
  * compute.instances.setMetadata (via VM's [instance metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-instance-metadata))
  * compute.projects.setCommonInstanceMetadata (via [project-wide metadata](https://cloud.google.com/compute/docs/metadata/setting-custom-metadata#set-custom-project-wide-metadata))
  * iam.serviceAccountUser role on the Instance's service account

**Mitigations**:

* Restrict and monitor the use of the compute.instances.setMetadata and compute.projects.setCommonInstanceMetadata permissions.
* Restrict and monitor the use of the iam.serviceAccountUser role
* Disable serial port access through [organization policy](https://cloud.google.com/compute/docs/troubleshooting/troubleshooting-using-serial-console#disabling_interactive_serial_console_access_through_organization_policy).
* [Disable the OS Config agent](https://cloud.google.com/compute/docs/manage-os#disable-agent) on the VM.

## **Conclusion**

This post provides an overview of potential attack paths into VMs and outlines the mitigation strategies that organizations can implement to enhance their cloud security. Maintaining the security posture of VMs in cloud environments is crucial.

Due to their widespread use and inherent permissions from workload identities, VMs are attractive targets for attackers. All the attack paths discussed throughout this post are based on the intended features of legitimate use cases. However, if these features are not properly secured, adversaries can abuse them with malicious intent. The responsibility of safeguarding these attack paths and mitigating potential risks lies with the cloud users.

IAM configuration plays a pivotal role in both enabling these attack paths and mitigating their associated risks. To ensure robust cloud security, it is vital to continuously identify these attack paths and monitor the use of risky permissions.

As cloud environments continue to evolve, so too will the TTPs employed by cyberattackers. Organizations must remain vigilant and proactive in their cloud security efforts, adapting their strategies to counter evolving threats.

### Palo Alto Networks Protection and Mitigation

Palo Alto Networks customers are better protected from the threats discussed above through the following products:

* [Prisma Cloud](https://docs.paloaltonetworks.com/prisma/prisma-cloud) customers are better protected by the [attack path policies](https://docs.prismacloud.io/en/classic/cspm-admin-guide/prisma-cloud-policies/attack-path-policies) that continuously monitor and alert potential attack paths.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response) detects and blocks exploits and evasive cloud-based attacks.
* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse) can detect shadow IT running in public cloud providers and help bring these resources under management.

If you think you may have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## **Additional Resources**

**Palo Alto Networks**

* [Prisma Cloud](https://docs.prismacloud.io/en/classic/cspm-admin-guide/get-started-with-prisma-cloud/prisma-cloud-how-it-works)
* [Prisma Cloud Vulnerability Management](https://www.paloaltonetworks.com/prisma/cloud/vulnerability-management)
* [Prisma Cloud attack path policies](https://docs.prismacloud.io/en/classic/cspm-admin-guide/prisma-cloud-policies/attack-path-policies)
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cloud-detection-and-response)
* [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html)
* [Unit 42 Cloud Threat Report](https://www.paloaltonetworks.com/prisma/unit42-cloud-threat-research)
* [Navigating the Cloud: Exploring Lateral Movement Techniques](https://unit42.paloaltonetworks.com/cloud-lateral-movement-techniques/)
* [When a Zero Day and Access Keys Collide in the Cloud: Responding to the SugarCRM Zero-Day Vulnerability](https://unit42.paloaltonetworks.com/sugarcrm-cloud-incident-black-hat/)
* [Cloud Keys in the Air](https://unit42.paloaltonetworks.com/malicious-operations-of-exposed-iam-keys-cryptojacking/)

**AWS**

* [Amazon Inspector](https://aws.amazon.com/inspector/)
* [Work with EC2 instance user data](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instancedata-add-user-data.html)
* [Run a script with every restart of EC2 instance](https://repost.aws/knowledge-center/execute-user-data-ec2)
* [EC2 Instance Connect](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connect-linux-inst-eic.html)
* [EC2 Instance Connect agent](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-set-up.html)
* [EC2 Instance Connect permissions](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-configure-IAM-role.html#eic-permissions-allow-users-to-connect-to-specific-instances)
* [Uninstall EC2 Instance Connect](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-connect-uninstall.html)
* [SSM Run Command](https://docs.aws.amazon.com/systems-manager/latest/userguide/run-command.html)
* [Install SSM agent](https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-manual-agent-install.html)
* [Uninstall the SSM agent](https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-uninstall-agent.html)
* [AmazonSSMManagedInstanceCore](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AmazonSSMManagedInstanceCore.html) policy
* [Restrict documents that SSM agent can execute](https://docs.aws.amazon.com/systems-manager/latest/userguide/security_iam_id-based-policy-examples.html#customer-managed-policies)
* [Default Host Management Configuration](https://docs.aws.amazon.com/systems-manager/latest/userguide/managed-instances-default-host-management.html#managed-instances-default-host-management-console)
* [SSM Session Manager](https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html)
* [Session Manager permissions](https://docs.aws.amazon.com/systems-manager/latest/userguide/getting-started-add-permissions-to-existing-profile.html)
* [Amazon EC2 Serial Console](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connect-to-serial-console.html)
* [Grant account access to the serial console](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configure-access-to-serial-console.html#sc-grant-account-access)
* [Instance types supporting serial console access](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-serial-console-prerequisites.html#sc-prereqs-instance-types)

**Azure**

* [Microsoft Defender for Cloud](https://azure.microsoft.com/en-us/products/defender-for-cloud)
* [VM custom data](https://learn.microsoft.com/en-us/azure/virtual-machines/custom-data)
* [Update VM scale set properties](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-upgrade-scale-set#how-to-update-global-scale-set-properties)
* [Command for updating the state of a VMSS](https://learn.microsoft.com/en-us/powershell/module/az.compute/update-azvmss?view=azps-11.3.0)
* [Invoke Azure VM reimage](https://learn.microsoft.com/en-us/powershell/module/az.compute/invoke-azvmreimage?view=azps-11.3.0)
* [VM Extensions](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/overview)
* [VMAccess Extension](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/vmaccess-linux)
* [Linux VM agent](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/agent-linux)
* [Permissions for installing VM Extensions](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/extensions-rmpolicy-howto-cli)
* [Command for managing user accounts for a VM](https://learn.microsoft.com/en-us/cli/azure/vm/user?view=azure-cli-latest)
* [Microsoft.Compute/virtualMachines/extensions](https://learn.microsoft.com/en-us/azure/templates/microsoft.compute/virtualmachines/extensions?pivots=deployment-language-bicep)
* [Run Command](https://learn.microsoft.com/en-us/azure/virtual-machines/run-command-overview)
* [Limiting access to Run Command](https://learn.microsoft.com/en-us/azure/virtual-machines/windows/run-command#limiting-access-to-run-command)
* [Custom Script Extension](https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/custom-script-linux)
* [Azure Serial Console](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-overview)
* [Enable/Disable Azure Serial Console at the subscription level](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/serial-console-enable-disable#subscription-level-enabledisable)
* [Azure Serial Console for Linux](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/linux/serial-console-linux)
* [Azure Serial Console for Windows](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/serial-console-windows)
* [Boot diagnostic](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/boot-diagnostics)
* [Permissions for serial console access](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-enable-disable#enabling-least-privilege-access-to-serial-console-using-rbac)
* [Enable and disable serial console](https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/serial-console-enable-disable?source=recommendations)
* [Control plane and data plane](https://learn.microsoft.com/en-us/azure/azure-resource-manager/management/control-plane-and-data-plane#control-plane)

**GCP**

* [Google Security Command Center](https://cloud.google.com/security/products/security-command-center?hl=en)
* [VM metadata](https://cloud.google.com/compute/docs/metadata/overview)
* [Predefined metadata keys](https://cloud.google.com/compute/docs/metadata/predefined-metadata-keys)
* [Metadata keys for Linux startup scripts](https://cloud.google.com/compute/docs/instances/startup-scripts/linux#metadata-keys)
* [Enable OS Config in metadata](https://cloud.google.com/compute/docs/manage-os#enable-metadata)
* [Install guest agent](https://cloud.google.com/compute/docs/images/guest-environment)
* [Restart or reboot a VM](https://cloud.google.com/compute/docs/instances/stop-start-instance)
* [Add SSH keys to VMs that use metadata-based SSH keys](https://cloud.google.com/compute/docs/connect/add-ssh-keys#metadata)
* [Restrict SSH keys from VMs](https://cloud.google.com/compute/docs/connect/restrict-ssh-keys#block-keys)
* [About OS Login](https://cloud.google.com/compute/docs/oslogin)
* [Enable OS Login](https://cloud.google.com/compute/docs/oslogin/set-up-oslogin#enable_os_login_for_all_vms_in_a_project)
* [Compute OS Login role](https://cloud.google.com/compute/docs/access/iam#compute.osLogin)
* [Compute OS Login External User role](https://cloud.google.com/compute/docs/access/iam#compute.osLoginExternalUser)
* [Set up OS Login with 2FA](https://cloud.google.com/compute/docs/oslogin/set-up-oslogin)
* [Enable security keys with OS Login](https://cloud.google.com/compute/docs/oslogin/security-keys)
* [VM Manager](https://cloud.google.com/compute/docs/vm-manager)
* [Compute Engine Patch](https://cloud.google.com/compute/docs/os-patch-management)
* [Create patch jobs](https://cloud.google.com/compute/docs/os-patch-management/create-patch-job)
* [Permissions for creating patch jobs](https://cloud.google.com/compute/docs/os-patch-management/create-patch-job#permissions)
* [Compute Engine OS Policy](https://cloud.google.com/compute/docs/os-configuration-management/working-with-os-policies#example-2)
* [Executing scripts in OS Policies](https://cloud.google.com/compute/docs/osconfig/rest/v1/projects.locations.osPolicyAssignments#execresource)
* [Permissions for creating OS policy assignment](https://cloud.google.com/compute/docs/os-configuration-management/create-os-policy-assignment#permissions)
* [Disable Patch or OS Policies in metadata](https://cloud.google.com/compute/docs/manage-os#disable-features)
* [Enable serial console](https://cloud.google.com/compute/docs/troubleshooting/troubleshooting-using-serial-console#enabling_interactive_access_on_the_serial_console)
* [Disable serial console access through organization policy](https://cloud.google.com/compute/docs/troubleshooting/troubleshooting-using-serial-console#disabling_interactive_serial_console_access_through_organization_policy)

**Others**

* [Bastion hosts](https://cloud.google.com/solutions/connecting-securely#bastion)
* [sshd configuration file](https://linux.die.net/man/5/sshd_config)
* [ssh authorized\_keys](https://linux.die.net/man/8/sshd)
* [Cyber Threat Alliance](https://www.cyberthreatalliance.org)

Back to top

### Tags

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")
* [Azure](https://unit42.paloaltonetworks.com/tag/azure/ "Azure")
* [IaaS](https://unit42.paloaltonetworks.com/tag/iaas/ "IaaS")
* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")
* [Virtual machines](https://unit42.paloaltonetworks.com/tag/virtual-machines/ "virtual machines")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia](https://unit42.paloaltonetworks.com/operation-diplomatic-specter/ "Operation Diplomatic Specter: An Active Chinese Cyberespionage Campaign Leverages Rare Tool Set to Target Governmental Entities in the Middle East, Africa and Asia")

### Table of Contents

* 

### Related Articles

* [How We Added WebAuthn to a Browser-Based RDP Client](https://unit42.paloaltonetworks.com/webauthn-added-to-browser-based-rdp/ "article - table of contents")
* [The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "article - table of contents")
* [Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools](https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/ "article - table of contents")

## Related Cloud Cybersecurity Research Resources

![Pictorial representation of bucket hijacking technique for cloud data exfiltration. Digital illustration of Europe map highlighting network connections and nodes, depicted as glowing points and lines on a dark blue background, emphasizing major cities and connectivity across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/09_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 22, 2026 [#### The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")

* [Bucket hijacking](https://unit42.paloaltonetworks.com/tag/bucket-hijacking/ "bucket hijacking")

* [Cloud data exfiltration](https://unit42.paloaltonetworks.com/tag/cloud-data-exfiltration/ "cloud data exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration")  
  ![Pictorial representation of Vertex AI model uploads. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/AdobeStock_1270203474-1-786x354.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 16, 2026 [#### Pickle in the Middle -- Hijacking Vertex AI Model Uploads for Cross-Tenant RCE](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/)

* [Bucket squatting](https://unit42.paloaltonetworks.com/tag/bucket-squatting/ "bucket squatting")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")

* [Joblib](https://unit42.paloaltonetworks.com/tag/joblib/ "joblib")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ "Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE")  
  ![Pictorial representation of Cloud Logging services for defense evasion. A vibrant digital illustration depicting a glowing, neon blue cloud symbol positioned over a circuit board landscape. The cloud symbolizes cloud computing technology, and the landscape features intricate electronic circuits with glowing lines and nodes, suggesting high-tech data transfer and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/11_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) June 9, 2026 [#### Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/)

* [AWS CloudTrail](https://unit42.paloaltonetworks.com/tag/aws-cloudtrail/ "AWS CloudTrail")

* [Cloud logging](https://unit42.paloaltonetworks.com/tag/cloud-logging/ "cloud logging")

* [Defense evasion](https://unit42.paloaltonetworks.com/tag/defense-evasion/ "defense evasion")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-logging-defense-evasion/ "Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility")  
  ![Pictorial representation of ROADtools framework in the cloud. An Asian man wearing glasses sits in front of a computer screen. Reflecting in the glasses are lines indicating analysis. Bright blue city lights illuminate the rest of the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/10_Cloud_cybersecurity_research_Overview_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) May 22, 2026 [#### Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/)

* [Curious Serpens](https://unit42.paloaltonetworks.com/tag/curious-serpens/ "Curious Serpens")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/ "Paved With Intent: ROADtools and Nation-State Tactics in the Cloud")  
  ![Pictorial representation of autonomous AI attack in cloud environments. Digital illustration of a glowing blue brain connected to a network of lines and lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/12_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 23, 2026 [#### Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Cloud](https://unit42.paloaltonetworks.com/tag/cloud/ "Cloud")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ "Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System")  
  ![Pictorial representation of passwordless authentication. Futuristic cityscape with skyscrapers surrounded by glowing, neon-lit pathways and digital clouds. The sky is vibrant with pink and orange hues, giving a surreal, cyberpunk aesthetic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/02_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) March 23, 2026 [#### Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication/)

* [Google](https://unit42.paloaltonetworks.com/tag/google/ "Google")

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication/ "Google Cloud Authenticator: The Hidden Mechanisms of Passwordless Authentication")  
  ![Close-up of a black woman with glasses examining colorful computer code on a screen. The scene is illuminated by various lights, creating a focused and analytical atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/13_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) February 6, 2026 [#### Novel Technique to Detect Cloud Threat Actor Operations](https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [IAM](https://unit42.paloaltonetworks.com/tag/iam/ "IAM")

* [MITRE](https://unit42.paloaltonetworks.com/tag/mitre/ "MITRE")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/tracking-threat-groups-through-cloud-logging/ "Novel Technique to Detect Cloud Threat Actor Operations")  
  ![Pictorial representation of Azure OpenAI DNS resolution issue. Futuristic cityscape illustration with luminous structures and floating cloud elements, showcasing advanced technology and a dynamic, digitally enhanced environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/02_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 20, 2026 [#### DNS OverDoS: Are Private Endpoints Too Private?](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/)

* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")

* [Networking](https://unit42.paloaltonetworks.com/tag/networking/ "networking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dos-attacks-and-azure-private-endpoint/ "DNS OverDoS: Are Private Endpoints Too Private?")  
  ![Pictorial representation of cloud discovery with AzureHound. A digital representation of a cloud composed of blue light particles, superimposed over a blurred background of server racks in a data center.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/08_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 24, 2025 [#### Cloud Discovery With AzureHound](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/)

* [Control plane](https://unit42.paloaltonetworks.com/tag/control-plane/ "control plane")

* [Curious Serpens](https://unit42.paloaltonetworks.com/tag/curious-serpens/ "Curious Serpens")

* [Data plane](https://unit42.paloaltonetworks.com/tag/data-plane/ "data plane")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-misuse-of-azurehound/ "Cloud Discovery With AzureHound")  
  ![Pictorial representation of a gift card fraud campaign. A glowing skull and crossbones on a circuit board.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/07_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 22, 2025 [#### Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign](https://unit42.paloaltonetworks.com/cloud-based-gift-card-fraud-campaign/)

* [CL‑CRI‑1032](https://unit42.paloaltonetworks.com/tag/cl-cri-1032/ "CL‑CRI‑1032")

* [Microsoft](https://unit42.paloaltonetworks.com/tag/microsoft/ "Microsoft")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cloud-based-gift-card-fraud-campaign/ "Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
