Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Multiple cloud snapshots export Informational Cloud 4 variations

    A cloud identity has downloaded multiple virtual machines or DB snapshots locally.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    2 Hours
    Deduplication:
    5 Days
    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Transfer Data to Cloud Account (T1537)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: Cloud Data Asset Exfiltration, Data Detection & Response
    Attacker's goals: Exfiltrate sensitive data that resides on the disk.
    Investigative actions: Check if the identity intended to export the virtual machines or DB snapshots. Check if the identity performed additional operations in the cloud environment that might be malicious.

    Variations

    Multiple cloud snapshots export

    High overridden

    A cloud identity has downloaded multiple virtual machines or DB snapshots from an external IP address. This action was unusual based on the cloud project history. overridden

    Multiple cloud snapshots export

    Medium overridden

    A cloud identity has downloaded multiple virtual machines or DB snapshots from an external IP address. This action was unusual based on The cloud identity history. overridden

    Multiple cloud snapshots export

    Low overridden

    A cloud identity has downloaded multiple virtual machines or DB snapshots locally. This action was unusual based on the unsuccessful attempts rate. overridden

    Multiple cloud snapshots export

    Low overridden

    A cloud identity has downloaded multiple virtual machines or DB snapshots locally. This action was unusual based on the cloud project or identity history. overridden