Suspicious ML Model Download
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud AI Infrastructure Analytics
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Cloud Storage (T1530)
Severity
Informational
Description
A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection.
Attacker's Goals
Adversaries may collect ML artifacts for exfiltration or for use in ML Attack Staging.
Investigative actions
Examine the bucket to determine which model was accessed.
Verify that this command was executed by a trusted source.
Variations
Was this helpful?
