Analytics BIOC
Informational
✕
An unusual read activity of cloud object
An identity accessed a cloud object filetype for the first time.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Data from Cloud Storage (T1530) Automated Exfiltration (T1020)
Detector tags: Cloud Data Asset Exfiltration
Attacker's goals:
Exfiltrate data from the cloud environment.
Investigative actions:
Check the identity which invoked the operation. Check the accessed resource and verify it doesn't contain sensitive data.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day