Analytics
Low
✕
Suspicious cloud user data modification attempt followed by VM restart
Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Cloud Administration Command (T1651)
Attacker's goals:
Execute arbitrary code, establish persistence, or alter instance startup behavior through modified user data.
Investigative actions:
Review the identity who modified the instance user data. Inspect the user data script for malicious content.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day