Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • Suspicious ML Model Download Informational Cloud 1 variation

    A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Data from Cloud Storage (T1530)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Adversaries may collect ML artifacts for exfiltration or for use in ML Attack Staging.
    Investigative actions: Examine the bucket to determine which model was accessed. Verify that this command was executed by a trusted source.

    Variations

    Suspicious First-Time AI Model Download by Identity

    Medium overridden

    A model artifact was accessed from cloud storage by an identity that did not interact with model files recently. overridden