Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1078 ✕
Download CSV Show ATT&CK heatmapCloud activity from a high-risk IP address Informational Cloud 1 variation
An identity executed a cloud API from a high-risk IP address.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003) Valid Accounts (T1078)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogDetector tags: OCI AnalyticsAttacker's goals: Gain initial access using a compromised identity while obfuscating origin.Investigative actions: Verify if the user is authorized to use anonymizing services. Review subsequent actions by the user for suspicious activity. Check for other users accessing from the same IP or tunnel operator.Variations
Cloud activity from an unusual high-risk IP
Low overridden
An identity executed a cloud API from a high-risk IP address. overridden