A cloud identity performed multiple unusual activities
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Medium
Description
A cloud identity performed multiple unusual activities across various cloud services.
Attacker's Goals
Adversaries may manipulate accounts to pivot to their next point in the environment, and eventually to access or manipulate data.
Investigative actions
Check if the identity intended to preform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Variations
PreviousA cloud identity invoked IAM related persistence operations
NextA cloud identity started a Cloud Shell session
Was this helpful?
