An identity accessed a backup cloud storage
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Exfiltration
ATT&CK Tactic
Collection (TA0009), Exfiltration (TA0010)
ATT&CK Technique
Data from Cloud Storage (T1530), Automated Exfiltration (T1020)
Severity
Informational
Description
An identity accessed a backup cloud storage.
Attacker's Goals
Exfiltrate data from the cloud environment.
Investigative actions
Check the identity which invoked the operation. Check the accessed resource and verify it doesn't contain sensitive data.
Variations
Was this helpful?
