Analytics BIOC Informational

Cloud compute serial console access

An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Direct Cloud VM Connections (T1021.008) Remote Services: Cloud Services (T1021.007)
Attacker's goals:

Utilize direct access to virtual infrastructure to pivot through a cloud environment.

Investigative actions:

Verify whether the identity should be making this action. Investigate which actions were performed via serial console access.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • Cloud compute serial console access by an identity with high administrative activity Informational
  • Suspicious cloud compute serial console access in a project Low (parent: Informational)