Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

7 alerts match the current filters. technique: T1651 ✕

Download CSV Show ATT&CK heatmap
  • AWS SSM association created with inventory collection document Informational Cloud 1 variation

    An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007) Execution (TA0002)
    ATT&CK techniques: Remote System Discovery (T1018) Cloud Administration Command (T1651)
    Required data: AWS Audit Log
    Detector tags: SSM Remote Management Analytics
    Attacker's goals: Enumerating managed hosts and installed software across the environment to identify targets for lateral movement or further exploitation.
    Investigative actions: Verify if the identity intended to create the SSM association. Examine the targets of the association to determine the scope of inventory collection. Follow further actions taken by the identity to detect potential lateral movement.

    Variations

    Unusual AWS SSM association created with inventory collection document

    Low overridden

    An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. overridden

  • AWS SSM send command attempt Informational Cloud 2 variations

    An identity executed an AWS SSM Document.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    3 Days
    ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
    ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Cloud Administration Command (T1651)
    Required data: AWS Audit Log
    Detector tags: Cloud Lateral Movement Analytics, SSM Remote Management Analytics
    Attacker's goals: Gaining unauthorized access, executing unauthorized commands, or compromising sensitive information within the target system.
    Investigative actions: Examine the code in the SSM document, and the target objects. Validate the permissions and roles associated with the user initiating the SSM session to ensure they align with the expected level of access. Follow further actions taken by the identity or on the relevant targets.

    Variations

    AWS SSM SendCommand targeting multiple instances

    Low overridden

    An identity executed an AWS SSM Document. overridden

    Unusual AWS SSM send command

    Low overridden

    An identity executed an AWS SSM Document. overridden

  • Azure VM extension abuse attempt Informational Cloud 1 variation

    A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Persistence (TA0003) Defense Evasion (TA0005)
    ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Account Manipulation (T1098) Impair Defenses: Disable or Modify Tools (T1562.001)
    Required data: Azure Audit Log
    Attacker's goals: Execute arbitrary code on VMs without network access (CustomScriptExtension). Gain persistent access by resetting local admin passwords (VMAccessExtension). Disable antimalware to deploy malware undetected (IaaSAntimalware deletion).
    Investigative actions: Identify the extension type involved (CustomScriptExtension, VMAccessExtension, IaaSAntimalware). For CustomScriptExtension: review the script payload executed on the VM. For VMAccessExtension: check if local admin credentials were reset and audit subsequent logins. For IaaSAntimalware deletion: verify the virtual machine audit log after the extension was removed. Verify whether the identity performing the operation is authorized to manage VM extensions. Check for correlated suspicious activity such as new role assignments or lateral movement.

    Variations

    Unusual azure VM extension abuse

    Low overridden

    A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. overridden

  • Azure virtual machine commands execution Informational Cloud 2 variations

    An Azure virtual machine executed PowerShell commands with System privileges.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    3 Hours
    ATT&CK tactics: Execution (TA0002) Lateral Movement (TA0008)
    ATT&CK techniques: Cloud Administration Command (T1651) Command and Scripting Interpreter: Cloud API (T1059.009) Remote Services: Cloud Services (T1021.007)
    Required data: Azure Audit Log
    Attacker's goals: Execute arbitrary code inside a VM without needing SSH/RDP or any open inbound network path.
    Investigative actions: Identify the target VM resource and the subscription / resource group it belongs to. Retrieve the script payload sent via Run Command. Verify whether the calling identity is normally entitled to perform VM Run Command on this VM. Check for related anomalies on the same identity.

    Variations

    Unusual Azure VM remote command execution

    Low overridden

    An Azure virtual machine executed PowerShell commands with System privileges. overridden

    First Azure VM remote command execution on this VM

    Informational overridden

    An Azure virtual machine executed PowerShell commands with System privileges. overridden

  • Cloud compute instance user data script modification Informational Cloud 1 variation

    The user data of a cloud compute instance was modified.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Cloud Administration Command (T1651)
    Required data: AWS Audit Log Gcp Audit Log
    Attacker's goals: Execute commands within virtual machines.
    Investigative actions: Verify whether this action is expected. Inspect the user data script for malicious content.

    Variations

    Unusual Cloud compute instance user data script modification

    Low overridden

    The user data of a cloud compute instance was modified. overridden

  • Command execution via AWS SSM Medium Cloud

    A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    30 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002) Lateral Movement (TA0008)
    ATT&CK techniques: Cloud Administration Command (T1651) Remote Services: Direct Cloud VM Connections (T1021.008)
    Required data: AWS Audit Log
    Attacker's goals: Gaining unauthorized access, executing unauthorized commands or compromising sensitive information within the target system.
    Investigative actions: Investigate the activities related to the suspected identity. Examine the code executed on the target instance(s).
  • Suspicious cloud user data modification attempt followed by VM restart Low Cloud

    Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Cloud Administration Command (T1651)
    Required data: AWS Audit Log Gcp Audit Log
    Attacker's goals: Execute arbitrary code, establish persistence, or alter instance startup behavior through modified user data.
    Investigative actions: Review the identity who modified the instance user data. Inspect the user data script for malicious content.