Analytics
Informational
✕
Suspicious secrets dump activity
An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Credential Access (TA0006) Collection (TA0009)
ATT&CK techniques: Unsecured Credentials (T1552) Data from Cloud Storage (T1530) Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)
Attacker's goals:
Collect secrets from the cloud environment.
Investigative actions:
Check the accessed secrets' designation. Verify that the identity did not dump any sensitive information that it shouldn't.
- Test period:
- 1 Hour
- Deduplication:
- 5 Days
2 variations:
- An identity extracted every secret within the organization across multiple regions Medium (parent: Informational)
- An identity extracted multiple secrets within the organization across multiple regions Low (parent: Informational)