Analytics BIOC
Informational
✕
Suspicious ML Model Download
A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Cloud Storage (T1530)
Detector tags: Cloud AI Infrastructure Analytics
Attacker's goals:
Adversaries may collect ML artifacts for exfiltration or for use in ML Attack Staging.
Investigative actions:
Examine the bucket to determine which model was accessed. Verify that this command was executed by a trusted source.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
1 variation:
- Suspicious First-Time AI Model Download by Identity Medium (parent: Informational)