Cloud activity from a high-risk IP address
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
OCI Analytics
ATT&CK Tactic
Initial Access (TA0001), Command and Control (TA0011)
ATT&CK Technique
Proxy: Multi-hop Proxy (T1090.003), Valid Accounts (T1078)
Severity
Informational
Description
An identity executed a cloud API from a high-risk IP address.
Attacker's Goals
Gain initial access using a compromised identity while obfuscating origin.
Investigative actions
Verify if the user is authorized to use anonymizing services.
Review subsequent actions by the user for suspicious activity.
Check for other users accessing from the same IP or tunnel operator.
Variations
Was this helpful?
