Analytics
Informational
✕
Abnormal Allocation of compute resources in multiple regions
An identity allocated an unusual compute resource pool, suspected as mining activity.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Impact (TA0040) Initial Access (TA0001)
ATT&CK techniques: Resource Hijacking (T1496) Valid Accounts (T1078)
Attacker's goals:
Leverage cloud compute resources to generate virtual currency.
Investigative actions:
Verify that the identity creating the resources is legitimate. Check for unusual behavior from this identity, including potential compromise (e.g., exposed access keys or service accounts).
- Test period:
- 30 Minutes
- Deduplication:
- 5 Days
4 variations:
- Abnormal Unusual allocation of compute resources in multiple regions High (parent: Informational)
- Abnormal Suspicious allocation of compute resources in multiple regions High (parent: Informational)
- Abnormal Allocation of compute resources in a high number of regions High (parent: Informational)
- Abnormal Allocation of compute resources in multiple regions by an unusual identity Low (parent: Informational)