Suspicious activity on logging bucket
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Log Tampering Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Informational
Description
An identity performed a suspicious activity on bucket used to store logs.
Attacker's Goals
Evade detection by tampering the logs.
Investigative actions
Verify whether the identity attempted to access the bucket.
Verify no logs were modified in the bucket.
Variations
PreviousSuspicious activity indicating a potential abuse of a cloud-native email service
NextSuspicious AI Dataset Download
Was this helpful?
