Analytics
Medium
✕
A cloud identity performed multiple unusual activities
A cloud identity performed multiple unusual activities across various cloud services.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Attacker's goals:
Adversaries may manipulate accounts to pivot to their next point in the environment, and eventually to access or manipulate data.
Investigative actions:
Check if the identity intended to preform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- A cloud identity performed multiple suspicious activities Low (parent: Medium)