Suspicious secrets dump activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Credential Access (TA0006), Collection (TA0009)
ATT&CK Technique
Unsecured Credentials (T1552), Data from Cloud Storage (T1530), Credentials from Password Stores: Cloud Secrets Management Stores (T1555.006)
Severity
Informational
Description
An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment.
Attacker's Goals
Collect secrets from the cloud environment.
Investigative actions
Check the accessed secrets' designation.
Verify that the identity did not dump any sensitive information that it shouldn't.
Variations
Was this helpful?
