Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Unusual cloud Instance Metadata Service (IMDS) access Informational Cloud 7 variations

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials: Cloud Instance Metadata API (T1552.005)
    Required data: XDR Agent
    Detector tags: Kubernetes - AGENT, Kubernetes Credentials Theft Analytics
    Attacker's goals: Extract sensitive cloud compute tokens to access restricted cloud resources.
    Investigative actions: Determine whether a web service was involved and if it was exploited to execute this technique. Identify any additional commands that were executed. Review the permissions assigned to the target machine to identify which resources may be affected. Examine related compute activity in the cloud audit logs.

    Variations

    Unusual cloud Instance Metadata Service (IMDS) access from a lightweight JavaScript runtime executing a script

    Medium overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden

    Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows web service

    Medium overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden

    Unusual cloud Instance Metadata Service (IMDS) access from an unusual known web service

    Medium overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden

    Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows shell process

    Medium overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden

    Unusual cloud Instance Metadata Service (IMDS) access from an unusual known shell process

    Medium overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden

    Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows scripting process

    Medium overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden

    Unusual cloud Instance Metadata Service (IMDS) access from an unusual known scripting process

    Low overridden

    A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. overridden