Analytics Informational

Unusual multi-region AWS Resource Explorer searches

An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Infrastructure Discovery (T1580) Account Discovery: Cloud Account (T1087.004)
Attacker's goals:

Obtain a list of resources that could be targeted for lateral movement.

Investigative actions:

Investigate any unusual activity originating from the suspected identity.

Test period:
1 Hour
Deduplication:
5 Days