Analytics BIOC
High
✕
Cloud penetration testing tool activity
A cloud API was successfully executed using a known cloud penetration testing tool.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Detector tags: Microsoft Graph Activity Logs
Attacker's goals:
Leverage known attack tools to enumerate resources, identify vulnerabilities, or exploit cloud configurations.
Investigative actions:
Confirm if authorized penetration testing activity is currently scheduled. Review the API operations performed by the identity to determine the intent and scope of the activity.
- Test period:
- N/A (single event)
- Deduplication:
- 7 Days
3 variations:
- Cloud penetration testing tool usage attempt Informational (parent: High)
- Cloud security assessment tool activity Low (parent: High)
- Cloud penetration testing tool activity by Azure application Informational (parent: High)