For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multiple risk indicators for a cloud identity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log

Detection Modules

Cloud

Detector Tags

OCI Analytics

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Valid Accounts (T1078), Valid Accounts: Cloud Accounts (T1078.004)

Severity

High

Description

Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP.

Attacker's Goals

Compromise a cloud user account to gain access and perform malicious activities.

Investigative actions

Review the user's recent activity for any unauthorized actions. Rotate the user's credentials immediately if confirmed compromised.

Was this helpful?