A commonly abused process connected to a rare cloud resource
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
EDR Windows C2 Analytics
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Application Layer Protocol: Web Protocols (T1071.001)
Severity
Low
Description
A commonly abused process connected to a rare cloud resource.
Attacker's Goals
Communicate with the attacker's Command and Control (C2) infrastructure.
Investigative actions
Investigate the actor process connected to the cloud resource.
Is this use case usually takes place within the org?
Determine if the cloud resource is owned by your organization or a known external entity.
Assess whether this communication pattern is expected or not.
Variations
PreviousA Command Line Interface (CLI) command was executed from an AWS serverless compute service
NextA commonly abused process connected to a rare external host
Was this helpful?
