Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud penetration testing tool activity High Cloud 3 variations

    A cloud API was successfully executed using a known cloud penetration testing tool.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    7 Days
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Microsoft Graph Logs
    Detector tags: Microsoft Graph Activity Logs
    Attacker's goals: Leverage known attack tools to enumerate resources, identify vulnerabilities, or exploit cloud configurations.
    Investigative actions: Confirm if authorized penetration testing activity is currently scheduled. Review the API operations performed by the identity to determine the intent and scope of the activity.

    Variations

    Cloud penetration testing tool usage attempt

    Informational overridden

    A failed cloud API was executed using a known cloud penetration testing tool. overridden

    Cloud security assessment tool activity

    Low overridden

    A cloud API was successfully executed using a known cloud security assessment tool. overridden

    Cloud penetration testing tool activity by Azure application

    Informational overridden

    A cloud API was successfully executed using a known cloud penetration testing tool by an Azure application. overridden