Analytics Medium

A cloud identity performed multiple unusual activities

A cloud identity performed multiple unusual activities across various cloud services.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Attacker's goals:

Adversaries may manipulate accounts to pivot to their next point in the environment, and eventually to access or manipulate data.

Investigative actions:

Check if the identity intended to preform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • A cloud identity performed multiple suspicious activities Low (parent: Medium)