Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud instance creation attempt Informational Cloud 2 variations

    An attempt was made to create a cloud compute instance.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Modify Cloud Compute Infrastructure: Create Cloud Instance (T1578.002)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Attacker's goals: Create a new cloud instance to evade detection or leverage it for further malicious activity.
    Investigative actions: Review recent activity related to the identity and the created cloud instance.

    Variations

    EC2 instance creation with admin profile, public IP address and external security group

    High overridden

    An attempt was made to create a cloud compute instance. overridden

    EC2 instance creation with admin profile and public IP address

    Medium overridden

    An attempt was made to create a cloud compute instance. overridden