Analytics Informational

Suspicious secrets dump activity

An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Credential Access (TA0006) Collection (TA0009)
ATT&CK techniques: Unsecured Credentials (T1552) Data from Cloud Storage (T1530) Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)
Attacker's goals:

Collect secrets from the cloud environment.

Investigative actions:

Check the accessed secrets' designation. Verify that the identity did not dump any sensitive information that it shouldn't.

Test period:
1 Hour
Deduplication:
5 Days
2 variations:
  • An identity extracted every secret within the organization across multiple regions Medium (parent: Informational)
  • An identity extracted multiple secrets within the organization across multiple regions Low (parent: Informational)