Analytics
Informational
✕
AWS Security Service Enumeration
AWS security service enumeration activity, potentially indicating reconnaissance.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Software Discovery (T1518) Software Discovery: Security Software Discovery (T1518.001) Cloud Infrastructure Discovery (T1580)
Attacker's goals:
Reconnaissance of security defenses to assess and identify exploitable weaknesses.
Investigative actions:
Review which API calls were executed and their frequency. Analyze the identity performing the actions. Inspect configurations of enumerated services.
- Test period:
- 15 Minutes
- Deduplication:
- 5 Days
1 variation:
- AWS Multiple Security Services Enumeration Informational