Analytics BIOC Informational

Uncommon cloud CLI tool usage

An uncommon execution of a cloud CLI tool.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: Cloud API (T1059.009)
Attacker's goals:

Abuse cloud APIs to execute malicious commands.

Investigative actions:

Check what cloud CLI commands were executed.* Verify which cloud resources may have been affected.

Test period:
N/A (single event)
Deduplication:
5 Days
4 variations:
  • Uncommon cloud CLI tool usage within a web server pod Low (parent: Informational)
  • Uncommon cloud CLI tool usage within a web server Low (parent: Informational)
  • Uncommon cloud CLI tool usage within a cloud instance Low (parent: Informational)
  • Uncommon cloud CLI tool usage within a Kubernetes pod Informational