T1525 CrowdStrike LogScale · LogScale

Detect Implant Internal Image in CrowdStrike LogScale

Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. AWS AMIs, GCP Images, Azure Images, and container registries such as ECR, ACR, and Docker Hub private registries can be backdoored. Unlike uploading malware to external infrastructure, this technique focuses on modifying or creating images within a victim's own cloud environment. If the infrastructure provisioning pipeline is configured to always pull the latest image, a backdoored image ensures persistent access to any newly spun-up instance.

MITRE ATT&CK

Tactic
Persistence
Technique
T1525 Implant Internal Image
Canonical reference
https://attack.mitre.org/techniques/T1525/

LogScale Detection Query

CrowdStrike LogScale (LogScale)
cql
#event_simpleName = "CloudApiCall"
| CloudApiAction = /CreateImage|RegisterImage|CopyImage|ImportImage|PutImage|CompleteLayerUpload/i
| eval risk_level = case {
    CloudApiUserType = "Root" : "critical";
    ExternalIP != "" AND ExternalIP != null : "high";
    * : "medium"
  }
| table timestamp, ComputerName, UserName, CloudApiAction, CloudApiService, ExternalIP, risk_level
| sort by timestamp desc
high severity medium confidence

Detects cloud image implanting operations via CrowdStrike Falcon cloud API telemetry.

Data Sources

CrowdStrike Falcon Cloud Security Events

Required Tables

CloudApiCall

False Positives & Tuning

  • CI/CD pipeline automation creating golden AMIs or base container images as part of a legitimate image build and push workflow (e.g., Packer, GitHub Actions, Jenkins pipelines)
  • Cloud operations engineers capturing VM images for disaster recovery, golden image refresh, or compliance-mandated snapshots
  • Infrastructure-as-code tools (Terraform, Pulumi, CDK) creating or modifying images during automated provisioning runs
  • Container registry mirroring jobs that replicate approved public images into an internal private registry for air-gapped or compliance use
  • Security teams creating forensic images from compromised instances as part of an incident response workflow
Download portable Sigma rule (.yml)

Other platforms for T1525


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1AWS AMI Creation from Existing Instance

    Expected signal: AWS CloudTrail event: EventName=CreateImage, EventSource=ec2.amazonaws.com. The event will include requestParameters with instanceId, name, and noReboot fields. A follow-up DescribeImages event will appear as the AMI status is checked. The actor's IAM ARN, source IP, and user agent (aws-cli) will be captured in UserIdentityArn, SourceIpAddress, and UserAgent fields.

  2. Test 2Docker Image Modification and Push to Local Registry

    Expected signal: Docker daemon logs will record the build and push operations. If Docker events are forwarded to Splunk via a log shipper (Filebeat, Splunk UF), events will show image build and push with the image name and tag. In Kubernetes environments, admission controller logs (OPA, Kyverno) will record any attempt to run this image. Container runtime security tools (Falco, Sysdig) will generate events for the image push.

  3. Test 3AWS ECR Image Push with Modified Tag

    Expected signal: AWS CloudTrail events: GetAuthorizationToken (ECR login), InitiateLayerUpload (begin push), UploadLayerPart (each image layer), CompleteLayerUpload (layer commit), and PutImage (finalize image with tag) — all with EventSource=ecr.amazonaws.com. All events include the actor IAM ARN, source IP, repository ARN, and user agent. The PutImage event includes imageManifest in requestParameters.

  4. Test 4Azure Container Registry Image Import

    Expected signal: Azure Activity Log event: OperationName=microsoft.containerregistry/registries/importimage/action, ResourceType=Microsoft.ContainerRegistry/registries, ActivityStatus=Succeeded. Includes Caller (UPN or service principal), CallerIpAddress, and ResourceId. The Azure Monitor diagnostic logs for ACR will also record the image push with repository, tag, and digest details.

Unlock Pro Content

Get the full detection package for T1525 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections