Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud impersonation attempt by unusual identity type Informational Cloud 2 variations

    A suspicious identity type has attempted to impersonate another identity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts (T1078) Trusted Relationship (T1199)
    Required data: AWS Audit Log Gcp Audit Log
    Attacker's goals: Escalate privileges to bypass access controls Avoid detection throughout their compromise.
    Investigative actions: Check the identity's designation. Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.

    Variations

    Cloud impersonation attempt of a management role by unusual identity type

    Informational overridden

    An unusual cloud identity type attempted to impersonate a management role. overridden

    Successful cloud impersonation by an unusual identity type

    Medium overridden

    A suspicious identity type has successfully impersonated another identity. overridden