Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapCloud compute serial console access Informational Cloud 2 variations
An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Remote Services: Cloud Services (T1021.007)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogAttacker's goals: Utilize direct access to virtual infrastructure to pivot through a cloud environment.Investigative actions: Verify whether the identity should be making this action. Investigate which actions were performed via serial console access.Variations
Cloud compute serial console access by an identity with high administrative activity
Informational overridden
An identity with high administrative activity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. overridden
Suspicious cloud compute serial console access in a project
Low overridden
An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. overridden