Analytics BIOC
Informational
✕
Compute activity in dormant cloud region
A compute resource was created or updated in a cloud region that has been dormant for this project.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Unused/Unsupported Cloud Regions (T1535)
Detector tags: OCI Analytics
Attacker's goals:
Create compute resources in unmonitored regions to evade detection for purposes such as hijacking resources or establishing persistence.
Investigative actions:
Verify if compute resources are authorized in this region. Terminate unauthorized compute resources and disable unused regions.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
3 variations:
- Compute activity in dormant cloud region from a non-VPN IP address Informational
- A cloud compute instance was created in a dormant region Medium (parent: Informational)
- Compute activity in dormant cloud region by a compromised AWS access key High (parent: Informational)