Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0040 ✕

Download CSV Show ATT&CK heatmap
  • Deletion of multiple cloud resources Informational Cloud 2 variations

    An identity deleted multiple cloud resources.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    30 Minutes
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Destruction (T1485)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: OCI Analytics
    Attacker's goals: Leverage access to the cloud to delete resources and cause damage to an organization's infrastructure.
    Investigative actions: Confirm the legitimacy of the suspected identity and what cloud resources have been deleted by the identity. Look for any unusual activity associated with the suspected identity and determine whether they are compromised.

    Variations

    Deletion of multiple cloud resources

    Medium overridden

    An identity deleted multiple cloud resources. This large volume of deleted cloud resources had not been seen across all projects for the last 30 days. overridden

    Deletion of multiple cloud resources

    Low overridden

    An identity deleted multiple cloud resources. This large volume of deleted cloud resources had not been seen in this project for the last 30 days. overridden