Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1537 ✕
Download CSV Show ATT&CK heatmapForeign account was granted permissions to S3 bucket via resource-based policy Informational Cloud 1 variation
Foreign account was granted access to S3 bucket.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: AWS Audit LogDetector tags: Cloud Data Asset Exfiltration, Data Detection & ResponseAttacker's goals: The attacker wants to maintain control over the resource.Investigative actions: Check if the {cloud_best_identity_match} intended to modify {aws_s3bucket_identifier} policy. Check the permissions that were granted to the {aws_grantee_project}. Restrict permissions for the {aws_grantee_project} if needed.Variations
Foreign account was granted permissions to S3 bucket via resource-based policy with suspicious indicators
Low overridden
Foreign account was granted access to S3 bucket. overridden