Analytics Low

Suspicious cloud user data modification attempt followed by VM restart

Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Cloud Administration Command (T1651)
Attacker's goals:

Execute arbitrary code, establish persistence, or alter instance startup behavior through modified user data.

Investigative actions:

Review the identity who modified the instance user data. Inspect the user data script for malicious content.

Test period:
1 Hour
Deduplication:
1 Day