Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1537 ✕
Download CSV Show ATT&CK heatmapA cloud storage object was copied to a foreign cloud account Medium Cloud 2 variations
A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: AWS Audit Log Azure Audit LogDetector tags: Cloud Data Asset Exfiltration, Cloud Data Asset Configuration, Data Detection & ResponseAttacker's goals: Exfiltrate data to a foreign account.Investigative actions: Check the legitimacy of the copy operation. Review further actions performed by the identity.Variations
A cloud storage object from a sensitive bucket was copied to a foreign cloud account from a production account
High overridden
A cloud storage object was copied or moved to a foreign cloud storage account from a production account. The destination account was either not monitored or not seen within your tenant for the last 30 days. overridden
A cloud storage object was copied to a foreign cloud account from a production account
Medium overridden
A cloud storage object was copied or moved to a foreign cloud storage account from a production account. The destination account was either not monitored or not seen within your tenant for the last 30 days. overridden