For the complete documentation index, see llms.txt. This page is also available as Markdown.

Unusual cross projects activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Trusted Relationship (T1199)

Severity

Low

Description

A suspicious activity between different cloud projects.

Attacker's Goals

Abuse an existing connection and pivot through multiple projects to find their target.

Investigative actions

  • Check if the identity intended to perform actions on the project.

  • Check the operations that were performed on the project {caller_project}.

  • Check if the identity performed additional operations in the cloud environment that might be malicious.

Variations

Suspicious cross projects activity

Synopsis

Field
Value

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Trusted Relationship (T1199)

Severity

Medium

Description

A suspicious activity between different cloud projects.

Attacker's Goals

Abuse an existing connection and pivot through multiple projects to find their target.

Investigative actions

  • Check if the identity intended to perform actions on the project.

  • Check the operations that were performed on the project {caller_project}.

  • Check if the identity performed additional operations in the cloud environment that might be malicious.

Was this helpful?