Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A cloud storage configuration was modified Informational Cloud

    A cloud storage configuration was modified.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Modify Cloud Compute Infrastructure (T1578)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: Cloud Data Asset Public Exposure, Cloud Data Asset Configuration, Data Detection & Response
    Attacker's goals: An attacker may use this API to grant storage access permission.
    Investigative actions: Check if the identity intended to modify the storage configuration. Check if the identity performed additional malicious operations in the cloud environment.