Uncommon access to cloud platforms' sensitive files by a scripting engine
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Credentials from Password Stores (T1555)
Severity
Informational
Description
A scripting engine has accessed sensitive cloud platforms' files.
Attacker's Goals
Gain access/control over internal cloud platforms or repositories.
Investigative actions
Investigate if the behavior is known to the user or part of known product's procedure.
Investigate if the actor processes command line contains malicious indicators or a script file.
Variations
Was this helpful?
