Analytics
Low
✕
Suspicious identity downloaded multiple objects from a bucket
An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Data from Cloud Storage (T1530) Automated Exfiltration (T1020)
Detector tags: Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:
Exfiltrate sensitive data from the cloud environment.
Investigative actions:
Check the accessed bucket and objects designation. Verify that the identity did not download any sensitive information that it shouldn't.
- Test period:
- 1 Hour
- Deduplication:
- 5 Days
3 variations:
- Suspicious identity with DevOps behavior downloaded multiple objects from a bucket Informational (parent: Low)
- Suspicious identity downloaded multiple objects from a bucket that contains sensitive files Medium (parent: Low)
- Suspicious identity downloaded multiple objects from a backup storage bucket Medium (parent: Low)