Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1537 ✕
Download CSV Show ATT&CK heatmapMultiple cloud snapshots export Informational Cloud 4 variations
A cloud identity has downloaded multiple virtual machines or DB snapshots locally.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 2 Hours
- Deduplication:
- 5 Days
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogDetector tags: Cloud Data Asset Exfiltration, Data Detection & ResponseAttacker's goals: Exfiltrate sensitive data that resides on the disk.Investigative actions: Check if the identity intended to export the virtual machines or DB snapshots. Check if the identity performed additional operations in the cloud environment that might be malicious.Variations
Multiple cloud snapshots export
High overridden
A cloud identity has downloaded multiple virtual machines or DB snapshots from an external IP address. This action was unusual based on the cloud project history. overridden
Multiple cloud snapshots export
Medium overridden
A cloud identity has downloaded multiple virtual machines or DB snapshots from an external IP address. This action was unusual based on The cloud identity history. overridden
Multiple cloud snapshots export
Low overridden
A cloud identity has downloaded multiple virtual machines or DB snapshots locally. This action was unusual based on the unsuccessful attempts rate. overridden
Multiple cloud snapshots export
Low overridden
A cloud identity has downloaded multiple virtual machines or DB snapshots locally. This action was unusual based on the cloud project or identity history. overridden