Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • An S3 replication policy to an unknown bucket was created Low Cloud 3 variations

    An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Transfer Data to Cloud Account (T1537)
    Required data: AWS Audit Log
    Detector tags: Cloud Data Asset Exfiltration, Cloud Data Asset Configuration, Data Detection & Response
    Attacker's goals: Exfiltrate data to an unknown bucket.
    Investigative actions: Check the legitimacy of the referenced destination bucket. Review further logs for the source bucket. Review further actions performed by the identity.

    Variations

    Unusual S3 replication policy to an unknown bucket was created

    Low overridden

    An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. The operation was not performed in your organization in the last 30 days. overridden

    An S3 replication policy to an unknown bucket was created by an admin identity

    Informational overridden

    An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. The identity has an administrative behavior. overridden

    An S3 replication policy to an unknown bucket was created - denied attempt

    Low overridden

    A denied attempt to create an S3 replication policy to an unknown bucket. overridden