Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapCloud impersonation attempt by unusual identity type Informational Cloud 2 variations
A suspicious identity type has attempted to impersonate another identity.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Valid Accounts (T1078) Trusted Relationship (T1199)Required data: AWS Audit Log Gcp Audit LogAttacker's goals: Escalate privileges to bypass access controls Avoid detection throughout their compromise.Investigative actions: Check the identity's designation. Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.Variations
Cloud impersonation attempt of a management role by unusual identity type
Informational overridden
An unusual cloud identity type attempted to impersonate a management role. overridden
Successful cloud impersonation by an unusual identity type
Medium overridden
A suspicious identity type has successfully impersonated another identity. overridden