Abnormal Allocation of compute resources in multiple regions
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
30 Minutes
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040), Initial Access (TA0001)
ATT&CK Technique
Resource Hijacking (T1496), Valid Accounts (T1078)
Severity
Informational
Description
An identity allocated an unusual compute resource pool, suspected as mining activity.
Attacker's Goals
Leverage cloud compute resources to generate virtual currency.
Investigative actions
Verify that the identity creating the resources is legitimate.
Check for unusual behavior from this identity, including potential compromise (e.g., exposed access keys or service accounts).
Variations
Was this helpful?
