Analytics BIOC Medium

A cloud storage object was copied to a foreign cloud account

A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Exfiltration Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:

Exfiltrate data to a foreign account.

Investigative actions:

Check the legitimacy of the copy operation. Review further actions performed by the identity.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • A cloud storage object from a sensitive bucket was copied to a foreign cloud account from a production account High (parent: Medium)
  • A cloud storage object was copied to a foreign cloud account from a production account Medium