A cloud storage configuration was modified
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Public Exposure, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Defense Evasion (TA0005)
ATT&CK Technique
Modify Cloud Compute Infrastructure (T1578)
Severity
Informational
Description
A cloud storage configuration was modified.
Attacker's Goals
An attacker may use this API to grant storage access permission.
Investigative actions
Check if the identity intended to modify the storage configuration.
Check if the identity performed additional malicious operations in the cloud environment.
PreviousA cloud snapshot of AWS database or storage was modified or shared
NextA cloud storage object was copied to a foreign cloud account
Was this helpful?
