Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud infrastructure discovery across multiple regions Informational Cloud 2 variations

    Discovery API calls were executed across multiple AWS regions.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    5 Days
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Cloud Infrastructure Discovery (T1580)
    Required data: AWS Audit Log
    Attacker's goals: Discover resources across regions to understand the cloud deployment footprint. Target regions or services that may have weaker controls, lower visibility, or misconfiguration for potential exploitation. Build a complete view of infrastructure for lateral movement or privilege escalation.
    Investigative actions: Identify which services and regions were targeted. Analyze the identity performing the discovery. Correlate with other discovery or suspicious activities.

    Variations

    Cloud infrastructure discovery across multiple AWS services within a single region

    Informational overridden

    Discovery API calls were executed across multiple AWS regions. overridden

    Cloud infrastructure discovery across multiple AWS services and regions

    Low overridden

    Discovery API calls were executed across multiple AWS regions. overridden