Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A Cloud DB instance was exported to an unknown destination Informational Cloud

    A Cloud DB instance was exported to a foreign storage destination. The destination storage has not been seen in the organization in the last 30 days.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Transfer Data to Cloud Account (T1537)
    Required data: Gcp Audit Log
    Detector tags: Data Detection & Response, Cloud Data Asset Exfiltration
    Attacker's goals: Exfiltrate sensitive database content to an external or attacker-controlled bucket.
    Investigative actions: Verify if the destination bucket is authorized for data export. Investigate the identity performing the action for unusual behavior or lack of authorization. Assess the sensitivity of the data within the source Cloud DB instance to determine impact.