Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapCloud penetration testing tool activity High Cloud 3 variations
A cloud API was successfully executed using a known cloud penetration testing tool.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 7 Days
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)Required data: AWS Audit Log Azure Audit Log Gcp Audit Log Microsoft Graph LogsDetector tags: Microsoft Graph Activity LogsAttacker's goals: Leverage known attack tools to enumerate resources, identify vulnerabilities, or exploit cloud configurations.Investigative actions: Confirm if authorized penetration testing activity is currently scheduled. Review the API operations performed by the identity to determine the intent and scope of the activity.Variations
Cloud penetration testing tool usage attempt
Informational overridden
A failed cloud API was executed using a known cloud penetration testing tool. overridden
Cloud security assessment tool activity
Low overridden
A cloud API was successfully executed using a known cloud security assessment tool. overridden
Cloud penetration testing tool activity by Azure application
Informational overridden
A cloud API was successfully executed using a known cloud penetration testing tool by an Azure application. overridden