Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAWS Security Group remote access allowed from an unknown external IP address Low Cloud
A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)Required data: AWS Audit LogAttacker's goals: Obtaining persistency persistence by creating a direct, reliable backdoor that allows them to remotely control the system without needing to re-exploit it.Investigative actions: Investigate any unusual activity originating from the suspected identity and any activity performed from the newly added ip addresses.