Analytics BIOC Informational

Cloud impersonation attempt by unusual identity type

A suspicious identity type has attempted to impersonate another identity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078) Trusted Relationship (T1199)
Attacker's goals:

Escalate privileges to bypass access controls Avoid detection throughout their compromise.

Investigative actions:

Check the identity's designation. Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.

Test period:
N/A (single event)
Deduplication:
5 Days
2 variations:
  • Cloud impersonation attempt of a management role by unusual identity type Informational
  • Successful cloud impersonation by an unusual identity type Medium (parent: Informational)