Analytics Informational

Abnormal Allocation of compute resources in multiple regions

An identity allocated an unusual compute resource pool, suspected as mining activity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Impact (TA0040) Initial Access (TA0001)
ATT&CK techniques: Resource Hijacking (T1496) Valid Accounts (T1078)
Attacker's goals:

Leverage cloud compute resources to generate virtual currency.

Investigative actions:

Verify that the identity creating the resources is legitimate. Check for unusual behavior from this identity, including potential compromise (e.g., exposed access keys or service accounts).

Test period:
30 Minutes
Deduplication:
5 Days
4 variations:
  • Abnormal Unusual allocation of compute resources in multiple regions High (parent: Informational)
  • Abnormal Suspicious allocation of compute resources in multiple regions High (parent: Informational)
  • Abnormal Allocation of compute resources in a high number of regions High (parent: Informational)
  • Abnormal Allocation of compute resources in multiple regions by an unusual identity Low (parent: Informational)