Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • AWS Lambda Cross-Account sensitive permissions configured Low Cloud 3 variations

    A cloud identity has granted external AWS account sensitive permissions to a Lambda function.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Account Manipulation: Additional Cloud Roles (T1098.003) Account Manipulation (T1098)
    Required data: AWS Audit Log
    Attacker's goals: Obtaining persistency by using a Lambda function in the target's environment as a backdoor.
    Investigative actions: Investigate any unusual activity originating from the suspected identity. Investigate any unusual Lambda functions related operations originating from the allowed added accounts. Validate the legitimacy of the AWS accounts that were allowed external access.

    Variations

    AWS Lambda public sensitive permissions configured

    Medium overridden

    A cloud identity has granted public sensitive permissions to a Lambda function. overridden

    AWS Lambda public permissions configured

    Low overridden

    A cloud identity has granted public permissions to a Lambda function. overridden

    AWS Lambda Cross-Account permissions configured

    Informational overridden

    A cloud identity has granted an external AWS account permissions to a Lambda function. overridden