Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0007 ✕

Download CSV Show ATT&CK heatmap
  • Network sniffing detected in Cloud environment Informational Cloud 2 variations

    A network sniffing tool was used in a cloud environment.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Credential Access (TA0006) Discovery (TA0007)
    ATT&CK techniques: Network Sniffing (T1040)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Attacker's goals: Adversaries may sniff network traffic to capture information about an environment, including authentication material passed over the network.
    Investigative actions: Check the targeted resources and the sniffing policy. Check The cloud identity activity prior/after the network sniffing.

    Variations

    Unusual Network sniffing detected in Cloud environment

    Low overridden

    A network sniffing tool was used in a cloud environment. overridden

    Successful Network sniffing detected in Cloud environment

    Informational overridden

    A network sniffing tool was used in a cloud environment. overridden