Analytics Informational

Cloud infrastructure discovery across multiple regions

Discovery API calls were executed across multiple AWS regions.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Infrastructure Discovery (T1580)
Attacker's goals:

Discover resources across regions to understand the cloud deployment footprint. Target regions or services that may have weaker controls, lower visibility, or misconfiguration for potential exploitation. Build a complete view of infrastructure for lateral movement or privilege escalation.

Investigative actions:

Identify which services and regions were targeted. Analyze the identity performing the discovery. Correlate with other discovery or suspicious activities.

Test period:
1 Hour
Deduplication:
5 Days
2 variations:
  • Cloud infrastructure discovery across multiple AWS services within a single region Informational
  • Cloud infrastructure discovery across multiple AWS services and regions Low (parent: Informational)