For the complete documentation index, see llms.txt. This page is also available as Markdown.

Impossible travel by a cloud identity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

2 Hours

Deduplication Period

5 Days

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log

Detection Modules

Cloud

Detector Tags

OCI Analytics

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004)

Severity

Informational

Description

Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.

Attacker's Goals

Obtain and abuse credentials of cloud accounts.

Investigative actions

Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.

Variations

Impossible travel by an unusual cloud identity

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004)

Severity

Low

Description

Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account.

Attacker's Goals

Obtain and abuse credentials of cloud accounts.

Investigative actions

Verify if the identity's credentials have been compromised. Examine the recent activity of the identity in question.

Was this helpful?