Cortex XDR - Cloud IAM User Access Investigation

Investigate and respond to Cortex XDR Cloud alerts where a Cloud IAM user`s access key is used suspiciously to access the cloud environment. The following alerts are supported for AWS, Azure, and GCP environments. - Penetration testing tool attempt - Penetration testing tool activity - Suspicious API call from a Tor exit node

Pack
CloudIncidentResponse
Tasks
16

Inputs

Commands used