Analytics BIOC Informational

Cloud access key creation

Cloud access key creation by a cloud identity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Account Manipulation: Additional Cloud Credentials (T1098.001)
Attacker's goals:

Persist in the environment.

Investigative actions:

investigate the identity who created the access keys. Check the access key activity in the organization.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • Successful access key creation by an unusual identity type Informational
  • Unusual successful cloud access key creation Informational