Analytics BIOC Low

A Backup vault policy was modified

A cloud identity has modified backup vault access policy.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:

Manipulate access to a backup vault.

Investigative actions:

Check if the {identity_name} intended to modify the backup vault policy. Check additional activity by {identity_name}.

Test period:
N/A (single event)
Deduplication:
5 Days