Analytics BIOC Informational

Unusual user-agent for a cloud identity

A cloud identity has executed an API call with an unusual user-agent.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003) Privilege Escalation (TA0004) Defense Evasion (TA0005)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004)
Detector tags: OCI Analytics
Attacker's goals:

Evade detection by using non-standard tools or scripts.

Investigative actions:

Examine the recent actions of the user for any abnormal or unauthorized behavior. Verify if the user intentionally used a new device or tool.

Test period:
N/A (single event)
Deduplication:
5 Days
1 variation:
  • Unusual user-agent for a cloud identity by a compromised AWS access key Medium (parent: Informational)