Analytics
Low
✕
New cloud identity created with administrative policy
New cloud identity was created and assigned administrative policy.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create Account: Cloud Account (T1136.003) Create Account (T1136) Account Manipulation: Additional Cloud Credentials (T1098.001)
Attacker's goals:
Escalate privileges in cloud environments.
Investigative actions:
Confirm whether this activity was intentional. Check for other API calls that were executed by the identity. Look for any suspicious behavior from the IAM user/role to whom the administrative policy was attached.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- Administrative IAM User Created with Credentials Low