Analytics Informational

Allocation of multiple cloud compute resources

An identity allocated multiple compute resources.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Impact (TA0040) Initial Access (TA0001)
ATT&CK techniques: Resource Hijacking (T1496) Valid Accounts (T1078)
Attacker's goals:

Leverage cloud compute resources to earn virtual currency.

Investigative actions:

Check the identity created resources and its legitimacy. Look for any unusual behavior originated from the suspected identity, and check if they're compromised, e.g. Access key, service account, etc.

Test period:
1 Hour
Deduplication:
5 Days
5 variations:
  • Unusual allocation of multiple cloud compute resources High (parent: Informational)
  • Unusual allocation of multiple cloud compute resources Medium (parent: Informational)
  • Unusual allocation of multiple cloud compute resources Medium (parent: Informational)
  • Allocation of multiple cloud compute resources with accelerator gear Low (parent: Informational)
  • Unusual allocation attempt of multiple cloud compute resources Low (parent: Informational)