Analytics BIOC Informational

AWS support case creation

A cloud identity has created a new case in AWS support.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007) Privilege Escalation (TA0004)
ATT&CK techniques: Cloud Infrastructure Discovery (T1580) Account Manipulation (T1098)
Attacker's goals:

Obtaining a list of resources that could be targeted for lateral movement or convincing AWS's support to perform actions on their behalf.

Investigative actions:

Investigate any unusual activity originating from the suspected identity. View the contents of the newly created case {case_id} .

Test period:
N/A (single event)
Deduplication:
5 Days