Deletion of multiple cloud resources
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
30 Minutes
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
OCI Analytics
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Data Destruction (T1485)
Severity
Informational
Description
An identity deleted multiple cloud resources.
Attacker's Goals
Leverage access to the cloud to delete resources and cause damage to an organization's infrastructure.
Investigative actions
Confirm the legitimacy of the suspected identity and what cloud resources have been deleted by the identity.
Look for any unusual activity associated with the suspected identity and determine whether they are compromised.
Variations
PreviousDeletion of AD CS certificate database entries
NextDenied API call by a Kubernetes service account
Was this helpful?
