Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapA cloud identity created or modified a security group Informational Cloud 2 variations
A cloud identity created or modified a security group.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogAttacker's goals: Bypass network security controls to gain access to restricted cloud resources.Investigative actions: Check which security rules were added or modified. Check whether the identity that modified the security group rules is permitted to perform such action. Check which cloud resources can be affected by the security group.Variations
A cloud identity opened a security group to the Internet
Medium overridden
A cloud identity modified a security group to allow network access from the Internet. overridden
A cloud identity opened a security group to an unknown IP
Low overridden
A cloud identity modified a security group to allow network access from an unknown IP. overridden