Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAWS Lambda Cross-Account sensitive permissions configured Low Cloud 3 variations
A cloud identity has granted external AWS account sensitive permissions to a Lambda function.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003) Account Manipulation (T1098)Required data: AWS Audit LogAttacker's goals: Obtaining persistency by using a Lambda function in the target's environment as a backdoor.Investigative actions: Investigate any unusual activity originating from the suspected identity. Investigate any unusual Lambda functions related operations originating from the allowed added accounts. Validate the legitimacy of the AWS accounts that were allowed external access.Variations
AWS Lambda public sensitive permissions configured
Medium overridden
A cloud identity has granted public sensitive permissions to a Lambda function. overridden
AWS Lambda public permissions configured
Low overridden
A cloud identity has granted public permissions to a Lambda function. overridden
AWS Lambda Cross-Account permissions configured
Informational overridden
A cloud identity has granted an external AWS account permissions to a Lambda function. overridden