Analytics BIOC
Informational
✕
Cloud impersonation attempt by unusual identity type
A suspicious identity type has attempted to impersonate another identity.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078) Trusted Relationship (T1199)
Attacker's goals:
Escalate privileges to bypass access controls Avoid detection throughout their compromise.
Investigative actions:
Check the identity's designation. Verify that the identity did not perform sensitive operation on behalf of the impersonated identity.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
2 variations:
- Cloud impersonation attempt of a management role by unusual identity type Informational
- Successful cloud impersonation by an unusual identity type Medium (parent: Informational)