Analytics Low

New cloud identity created with administrative policy

New cloud identity was created and assigned administrative policy.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create Account: Cloud Account (T1136.003) Create Account (T1136) Account Manipulation: Additional Cloud Credentials (T1098.001)
Attacker's goals:

Escalate privileges in cloud environments.

Investigative actions:

Confirm whether this activity was intentional. Check for other API calls that were executed by the identity. Look for any suspicious behavior from the IAM user/role to whom the administrative policy was attached.

Test period:
1 Hour
Deduplication:
1 Day
1 variation:
  • Administrative IAM User Created with Credentials Low