Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAzure storage account cross-tenant object replication was enabled Informational Cloud 1 variation
Azure cross-tenant object replication in a storage account was enabled.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: Azure Audit LogDetector tags: Cloud Data Asset Stealth Tactics, Cloud Data Asset Exfiltration, Data Detection & ResponseAttacker's goals: Enable unauthorized data transfer to an external or attacker-controlled environment. Establish a persistent channel for ongoing data exfiltration. Conceal malicious activity by utilizing legitimate cross-tenant object replication functionality.Investigative actions: Confirm that the identity intended to enable cross-tenant replication. Follow further actions done by the identity. Monitor the storage account for other suspicious activities.Variations
Azure storage account cross-tenant object replication was enabled for the first time in a subscription
Low overridden
Azure cross-tenant object replication in a storage account was enabled for the first time in a subscription. overridden