Unusual AWS SageMaker notebook access
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud AI Infrastructure Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Command and Scripting Interpreter: Cloud API (T1059.009)
Severity
Informational
Description
A cloud identity accessed an AWS SageMaker notebook for the first time. MITRE ATLAS Technique: AML.T0008 - Acquire Infrastructure: AI Development Workspaces.
Attacker's Goals
Gain access to AI/ML resources and services.
Investigative actions
Examine which AWS SageMaker notebooks were accessed.
Investigate any unusual activity originating from the suspected identity.
Was this helpful?
