Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapSuspicious ML Model Download Informational Cloud 1 variation
A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 5 Days
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Cloud Storage (T1530)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogDetector tags: Cloud AI Infrastructure AnalyticsAttacker's goals: Adversaries may collect ML artifacts for exfiltration or for use in ML Attack Staging.Investigative actions: Examine the bucket to determine which model was accessed. Verify that this command was executed by a trusted source.Variations
Suspicious First-Time AI Model Download by Identity
Medium overridden
A model artifact was accessed from cloud storage by an identity that did not interact with model files recently. overridden