AWS CreateAssociation
Creates a Systems Manager State Manager association.
The adversary is trying to run malicious code.
Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.
In cloud environments, execution commonly involves invoking serverless functions (Lambda, Cloud Functions), running commands through instance metadata services, or leveraging cloud-native automation tools like SSM, CloudFormation, or Azure Automation. Adversaries may also abuse cloud shells and container orchestration platforms.
View Execution on MITRE ATT&CK →Explore this tactic in the map.
Creates a Systems Manager State Manager association.
Requests provisioning of a CloudFormation stack from a template.
Requests synchronous, asynchronous, or dry-run Lambda invocation.
Creates an Azure Automation runbook job.
Creates or updates an Azure Automation runbook resource.
Creates or updates an extension on an Azure virtual machine.
Requests script execution through Azure VM Action Run Command.
Requests execution of a command through AKS Run Command.
Changes a supported EC2 instance attribute, including user data or security groups.
Reconnects to a disconnected SSM Session Manager session.
Submits an SSM Run Command document to managed nodes.
Starts a CodeBuild build with optional execution overrides.
Starts an SSM Session Manager session.