Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0010 ✕

Download CSV Show ATT&CK heatmap
  • Foreign account was granted permissions to S3 bucket via resource-based policy Informational Cloud 1 variation

    Foreign account was granted access to S3 bucket.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Transfer Data to Cloud Account (T1537)
    Required data: AWS Audit Log
    Detector tags: Cloud Data Asset Exfiltration, Data Detection & Response
    Attacker's goals: The attacker wants to maintain control over the resource.
    Investigative actions: Check if the {cloud_best_identity_match} intended to modify {aws_s3bucket_identifier} policy. Check the permissions that were granted to the {aws_grantee_project}. Restrict permissions for the {aws_grantee_project} if needed.

    Variations

    Foreign account was granted permissions to S3 bucket via resource-based policy with suspicious indicators

    Low overridden

    Foreign account was granted access to S3 bucket. overridden