Cloud penetration testing tool activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
7 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
High
Description
A cloud API was successfully executed using a known cloud penetration testing tool.
Attacker's Goals
Leverage known attack tools to enumerate resources, identify vulnerabilities, or exploit cloud configurations.
Investigative actions
Confirm if authorized penetration testing activity is currently scheduled.
Review the API operations performed by the identity to determine the intent and scope of the activity.
Variations
Was this helpful?
