Analytics Informational

Storage enumeration activity

An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Storage Object Discovery (T1619) Cloud Infrastructure Discovery (T1580)
Detector tags: Cloud Data Asset Stealth Tactics Data Detection & Response
Attacker's goals:

Access sensitive data stored in cloud infrastructure.

Investigative actions:

Check the identity's role designation in the organization. Identify which storage buckets were enumerated and whether they contained sensitive information.

Test period:
10 Minutes
Deduplication:
5 Days