Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Compute activity in dormant cloud region Informational Cloud 3 variations

    A compute resource was created or updated in a cloud region that has been dormant for this project.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Unused/Unsupported Cloud Regions (T1535)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: OCI Analytics
    Attacker's goals: Create compute resources in unmonitored regions to evade detection for purposes such as hijacking resources or establishing persistence.
    Investigative actions: Verify if compute resources are authorized in this region. Terminate unauthorized compute resources and disable unused regions.

    Variations

    Compute activity in dormant cloud region from a non-VPN IP address

    Informational overridden

    A compute resource was created or updated in a cloud region that has been dormant for this project. overridden

    A cloud compute instance was created in a dormant region

    Medium overridden

    A compute resource was created or updated in a cloud region that has been dormant for this project. overridden

    Compute activity in dormant cloud region by a compromised AWS access key

    High overridden

    A compute resource was created or updated in a cloud region that has been dormant for this project. overridden