Network sniffing detected in Cloud environment
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006), Discovery (TA0007)
ATT&CK Technique
Network Sniffing (T1040)
Severity
Informational
Description
A network sniffing tool was used in a cloud environment.
Attacker's Goals
Adversaries may sniff network traffic to capture information about an environment, including authentication material passed over the network.
Investigative actions
Check the targeted resources and the sniffing policy.
Check The cloud identity activity prior/after the network sniffing.
Variations
Was this helpful?
