Analytics BIOC Informational

Uncommon access to cloud platforms' sensitive files by a scripting engine

A scripting engine has accessed sensitive cloud platforms' files.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores (T1555)
Attacker's goals:

Gain access/control over internal cloud platforms or repositories.

Investigative actions:

Investigate if the behavior is known to the user or part of known product's procedure. Investigate if the actor processes command line contains malicious indicators or a script file.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Uncommon access to cloud platforms' sensitive files by an uncommon script or utility Low (parent: Informational)