Analytics BIOC
Informational
✕
Cloud activity from a high-risk IP address
An identity executed a cloud API from a high-risk IP address.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)
ATT&CK techniques: Proxy: Multi-hop Proxy (T1090.003) Valid Accounts (T1078)
Detector tags: OCI Analytics
Attacker's goals:
Gain initial access using a compromised identity while obfuscating origin.
Investigative actions:
Verify if the user is authorized to use anonymizing services. Review subsequent actions by the user for suspicious activity. Check for other users accessing from the same IP or tunnel operator.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
1 variation:
- Cloud activity from an unusual high-risk IP Low (parent: Informational)