Analytics Low

Suspicious identity downloaded multiple objects from a bucket

An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Data from Cloud Storage (T1530) Automated Exfiltration (T1020)
Detector tags: Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:

Exfiltrate sensitive data from the cloud environment.

Investigative actions:

Check the accessed bucket and objects designation. Verify that the identity did not download any sensitive information that it shouldn't.

Test period:
1 Hour
Deduplication:
5 Days
3 variations:
  • Suspicious identity with DevOps behavior downloaded multiple objects from a bucket Informational (parent: Low)
  • Suspicious identity downloaded multiple objects from a bucket that contains sensitive files Medium (parent: Low)
  • Suspicious identity downloaded multiple objects from a backup storage bucket Medium (parent: Low)