Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • AWS Backup vault was deleted Informational Cloud 2 variations

    An AWS Backup vault was deleted by a cloud identity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Inhibit System Recovery (T1490)
    Required data: AWS Audit Log
    Detector tags: Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & Response
    Attacker's goals: Destroy all backup data stored in the vault to prevent recovery after a ransomware or destructive attack. Deleting a vault is more impactful than deleting individual recovery points as it wipes all backups at once.
    Investigative actions: Confirm that the identity intended to delete this backup vault. Determine whether the vault contained recovery points for critical resources. Review further actions performed by the identity. Check whether other backup vaults or recovery points remain for the affected resources.

    Variations

    AWS Backup vault was deleted from a production account

    Low overridden

    An AWS Backup vault was deleted by a cloud identity. The backup vault was deleted from a production account. overridden

    AWS Backup vault was deleted for the first time by this identity

    Low overridden

    An AWS Backup vault was deleted by a cloud identity. This is the first time this identity has deleted an AWS Backup vault. overridden