Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAWS IAM Role Created with Cross-Account Access Low Cloud 1 variation
A cloud identity has created a new IAM role with trust policy that allows external AWS account access.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003) Account Manipulation (T1098)Required data: AWS Audit LogAttacker's goals: Obtaining persistency by assuming a role in the target's environment.Investigative actions: Investigate any unusual activity originating from the suspected identity. Investigate any unusual activity performed in the assumed role sessions when originating from the allowed added accounts. Validate the legitimacy of the AWS accounts that were allowed external access.Variations
AWS IAM Role Created with Cross-Account Access using CloudFormation
Informational overridden
A cloud identity has created a new IAM role with trust policy that allows external AWS account access. overridden