Analytics BIOC
Informational
✕
Unusual Identity and Access Management (IAM) activity
A cloud identity performed an unusual IAM operation.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
ATT&CK techniques: Account Manipulation: Additional Cloud Credentials (T1098.001) Valid Accounts: Cloud Accounts (T1078.004)
Attacker's goals:
Manipulate IAM configuration to strengthen the foothold in the cloud environment of the organization, by creating new accounts, modifying credentials, and permissions. Using the modified accounts, the attacker may perform additional activities in an evasive manner.
Investigative actions:
Check the identity's role designation in the organization. Verify that the identity did not perform any sensitive IAM operation that it shouldn't.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
2 variations:
- Unusual Identity and Access Management (IAM) activity executed from a cloud Internet facing instance Medium (parent: Informational)
- Unusual Identity and Access Management (IAM) activity Low (parent: Informational)