Analytics BIOC Informational

A cloud identity created or modified a security group

A cloud identity created or modified a security group.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Cloud Firewall (T1562.007)
Attacker's goals:

Bypass network security controls to gain access to restricted cloud resources.

Investigative actions:

Check which security rules were added or modified. Check whether the identity that modified the security group rules is permitted to perform such action. Check which cloud resources can be affected by the security group.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • A cloud identity opened a security group to the Internet Medium (parent: Informational)
  • A cloud identity opened a security group to an unknown IP Low (parent: Informational)