Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Impossible travel by a cloud identity Informational Cloud 1 variation

    Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    2 Hours
    Deduplication:
    5 Days
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: OCI Analytics
    Attacker's goals: Obtain and abuse credentials of cloud accounts.
    Investigative actions: Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.

    Variations

    Impossible travel by an unusual cloud identity

    Low overridden

    Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. overridden