Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1199 ✕

Download CSV Show ATT&CK heatmap
  • Unusual cross projects activity Low Cloud 1 variation

    A suspicious activity between different cloud projects.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Trusted Relationship (T1199)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Attacker's goals: Abuse an existing connection and pivot through multiple projects to find their target.
    Investigative actions: Check if the identity intended to perform actions on the project. Check the operations that were performed on the project {caller_project}. Check if the identity performed additional operations in the cloud environment that might be malicious.

    Variations

    Suspicious cross projects activity

    Medium overridden

    A suspicious activity between different cloud projects. overridden