Analytics BIOC
Informational
✕
Unusual cloud identity impersonation
A cloud identity attempted to impersonate another identity for the first time.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Gcp Audit Log
ATT&CK tactics: Privilege Escalation (TA0004) Defense Evasion (TA0005) Initial Access (TA0001)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005) Trusted Relationship (T1199)
Attacker's goals:
Escalate privileges and bypass access controls Avoid detection throughout their compromise.
Investigative actions:
Check the identity's designation. Verify that the identity did not perform any sensitive operation on behalf of the impersonated identity.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
3 variations:
- Unusual cloud identity impersonation of a management role Informational
- Suspicious cloud identity impersonation was succeeded Medium (parent: Informational)
- Suspicious cloud identity impersonation was failed Informational