Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • An AWS EC2 instance containing sensitive data was exported Informational Cloud

    A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    3 Days
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Transfer Data to Cloud Account (T1537)
    Required data: AWS Audit Log
    Detector tags: Cloud Data Asset Stealth Tactics, Data Detection & Response
    Attacker's goals: An attack may exfiltrate data from an EC2 instance to an S3 bucket outside the account.
    Investigative actions: Check the identity that exported the instance. Check to which S3 bucket the EC2 was exported into. Check the S3 bucket permission and policy.