Analytics
Informational
✕
Impossible travel by a cloud identity
Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004)
Detector tags: OCI Analytics
Attacker's goals:
Obtain and abuse credentials of cloud accounts.
Investigative actions:
Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.
- Test period:
- 2 Hours
- Deduplication:
- 5 Days
1 variation:
- Impossible travel by an unusual cloud identity Low (parent: Informational)