Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • GCP Firewall Rule creation Informational Cloud

    A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    3 Hours
    ATT&CK tactics: Defense Impairment (TA0112)
    ATT&CK techniques: Disable or Modify System Firewall: Cloud Firewall (T1686.001)
    Required data: Gcp Audit Log
    Attacker's goals: Access restricted resources.
    Investigative actions: Check if there were any network attempts that fit the created rule. Check the cloud identity activity before and after the rule creation.