Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1537 ✕
Download CSV Show ATT&CK heatmapA Backup vault policy was modified Low Cloud
A cloud identity has modified backup vault access policy.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: AWS Audit LogDetector tags: Cloud Data Asset Configuration, Data Detection & ResponseAttacker's goals: Manipulate access to a backup vault.Investigative actions: Check if the {identity_name} intended to modify the backup vault policy. Check additional activity by {identity_name}.