Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1552 ✕
Download CSV Show ATT&CK heatmapUnusual key management activity Informational Cloud
A cloud identity performed a key management operation for the first time.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials (T1552)Required data: AWS Audit Log Azure Audit Log Gcp Audit LogAttacker's goals: Abuse exposed cryptographic keys to decrypt sensitive information or create digital signatures to craft malicious messages. Using the decrypted information, the attacker may perform additional activities in an evasive manner.Investigative actions: Check the identity's role designation in the organization. Verify that the identity did not perform any sensitive KMS operation that it shouldn't.