Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access Low Cloud

    A cloud identity has updated an IAM role's trust policy to allow external AWS account access.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003) Account Manipulation (T1098)
    Required data: AWS Audit Log
    Attacker's goals: Obtaining persistency by assuming a role in the target's environment.
    Investigative actions: Investigate any unusual activity originating from the suspected identity. Investigate any unusual activity performed in the assumed role sessions when originating from the allowed added accounts. Validate the legitimacy of the AWS accounts that were allowed external access.