Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0040 ✕ technique: T1078 ✕
Download CSV Show ATT&CK heatmapAbnormal Allocation of compute resources in multiple regions Informational Cloud 4 variations
An identity allocated an unusual compute resource pool, suspected as mining activity.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 30 Minutes
- Deduplication:
- 5 Days
ATT&CK tactics: Impact (TA0040) Initial Access (TA0001)ATT&CK techniques: Resource Hijacking (T1496) Valid Accounts (T1078)Required data: AWS Audit Log Gcp Audit LogAttacker's goals: Leverage cloud compute resources to generate virtual currency.Investigative actions: Verify that the identity creating the resources is legitimate. Check for unusual behavior from this identity, including potential compromise (e.g., exposed access keys or service accounts).Variations
Abnormal Unusual allocation of compute resources in multiple regions
High overridden
An identity allocated an unusual compute resource pool, suspected as mining activity. overridden
Abnormal Suspicious allocation of compute resources in multiple regions
High overridden
An identity allocated an unusual compute resource pool, suspected as mining activity. overridden
Abnormal Allocation of compute resources in a high number of regions
High overridden
An identity allocated an unusual compute resource pool, suspected as mining activity. overridden
Abnormal Allocation of compute resources in multiple regions by an unusual identity
Low overridden
An identity allocated an unusual compute resource pool, suspected as mining activity. overridden