Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A cloud identity created or modified a security group Informational Cloud 2 variations

    A cloud identity created or modified a security group.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Attacker's goals: Bypass network security controls to gain access to restricted cloud resources.
    Investigative actions: Check which security rules were added or modified. Check whether the identity that modified the security group rules is permitted to perform such action. Check which cloud resources can be affected by the security group.

    Variations

    A cloud identity opened a security group to the Internet

    Medium overridden

    A cloud identity modified a security group to allow network access from the Internet. overridden

    A cloud identity opened a security group to an unknown IP

    Low overridden

    A cloud identity modified a security group to allow network access from an unknown IP. overridden