Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Cloud resource logging was disabled Informational Cloud 3 variations

    Cloud resource logging was disabled.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Logs (T1562.008)
    Required data: Azure Audit Log Gcp Audit Log
    Detector tags: Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Protection Tampering, Data Detection & Response
    Attacker's goals: Avoiding detection of their activities by limiting the amount of data collected. This action may be preliminary to resource deletion or data exhilaration from the resource. Setting the stage for further attacks, like a Ransomware Attack.
    Investigative actions: Confirm that the identity intended to disable logging on this resource. Follow further actions done by the identity. Monitor other (non-disabled) activity logs related to this resource.

    Variations

    Cloud resource logging was disabled - failed attempt

    Informational overridden

    A failed attempt to disable cloud resource logging. overridden

    Cloud resource logging was disabled on an Azure DB/storage resource

    Informational overridden

    Cloud resource logging was disabled on a DB/storage resource. overridden

    Cloud resource logging was disabled on a GCP DB/storage resource

    Low overridden

    Cloud resource logging was disabled on a DB/storage resource. overridden