An unusual read activity of cloud object
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Exfiltration
ATT&CK Tactic
Collection (TA0009), Exfiltration (TA0010)
ATT&CK Technique
Data from Cloud Storage (T1530), Automated Exfiltration (T1020)
Severity
Informational
Description
An identity accessed a cloud object filetype for the first time.
Attacker's Goals
Exfiltrate data from the cloud environment.
Investigative actions
Check the identity which invoked the operation. Check the accessed resource and verify it doesn't contain sensitive data.
PreviousAn unusual process in ingress-nginx has accessed a service-account token file
NextAnalytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert
Was this helpful?
