Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud compute serial console access Informational Cloud 2 variations

    An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Remote Services: Cloud Services (T1021.007)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Attacker's goals: Utilize direct access to virtual infrastructure to pivot through a cloud environment.
    Investigative actions: Verify whether the identity should be making this action. Investigate which actions were performed via serial console access.

    Variations

    Cloud compute serial console access by an identity with high administrative activity

    Informational overridden

    An identity with high administrative activity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. overridden

    Suspicious cloud compute serial console access in a project

    Low overridden

    An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. overridden