Analytics
Low
✕
ML artifacts destruction
An identity deleted multiple ML artifacts.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Data Destruction (T1485)
Detector tags: Cloud AI Infrastructure Analytics
Attacker's goals:
Leverage access to the cloud to delete resources and cause damage to an organization's infrastructure.
Investigative actions:
Confirm the legitimacy of the suspected identity and what cloud resources have been deleted by the identity. Look for any unusual activity associated with the suspected identity and determine whether they are compromised.
- Test period:
- 1 Hour
- Deduplication:
- 5 Days
1 variation:
- Unusual ML artifacts destruction Medium (parent: Low)