Cloud causality view for audit log issues
Investigate cloud attacks faster with entity context directly in the Cloud causality view.
The Cloud causality view presents entity context directly within issues, enabling security analysts to triage and scope cloud incidents in a single location. It displays the following context for a cloud audit log issue:
Caller IP and network intelligence: The network origin, scope, and reputation of the action.
Identity information: The acting identity profile, authentication behavior, and access privileges.
Target cloud asset details: Identifies the specific cloud asset(s) affected by this issue.
In this context, you can see who acted, how the identity was authenticated, what the identity accessed, and where the action originated, without switching tools.
The Cloud causality view shows cloud audit log issues as a source-to-destination graph, linking the identity or caller IP that initiated an action to the affected cloud asset. Cortex Cloud surfaces this context directly in the UAI by consolidating provider audit logs (Amazon Web Services CloudTrail, Microsoft Azure Activity Logs, and Google Cloud Platform Audit Logs).
The Cloud causality view presents cloud context for investigation and does not modify cloud provider configuration. From a case, drill down to a cloud audit log issue to open the Cloud causality view for that issue.
Use cases
Investigate the identity behind a cloud action: Select the identity node in the Cloud causality view to determine who performed the action and how the identity authenticated, and drill down to the identity name, identity type, cloud provider, and the identity that invoked the action.
Trace the origin of a cloud action: Select the caller IP node in the Cloud causality view to establish where the action originated, and drill down to the caller IP address, autonomous system number, and geolocation.
Assess the impact on a cloud resource: Select the destination node in the Cloud causality view to identify the affected cloud resource, and drill down to the resource name, referenced resource ID, resource type, and resource subtype.
Focus the investigation on a single entity: Select a node in the Cloud causality view to filter the bottom table to the issues related to the selected node, and review the related events with fields such as timestamp, cloud provider, project, region, identity name, and identity type.
Pivot to the full asset record: For an identity or a cloud resource that resolves to a Unified Assets Inventory (UAI) asset, open the asset card from the node to investigate the asset across the inventory, and review the identity and target cloud asset as the affected assets of the issue.
Supported platforms
The Cloud causality view supports cloud audit log issues and cases from the following cloud providers:
Amazon Web Services
Microsoft Azure
Google Cloud Platform
User roles and permissions
The Cloud causality view is available to users whose role grants access to issues and to cloud audit log data.
Node types
Each node type displays relevant details for your investigation, all conveniently accessible within a single window.
The Cloud causality view provides the caller IP node, identity node, and the destination node.
All events table
Select a node in the Cloud causality view to filter the bottom table to the issues related to the selected node. Cancel the node selection to return the bottom table to the unfiltered view.
UAI connection
When an identity or a target cloud asset in a cloud audit log issue resolves to an asset in the Unified Assets Inventory (UAI), the Cloud causality view connects the node to that asset. The connection aligns the investigation view with the inventory, so you access the complete asset record without searching the inventory separately. The Cloud causality view connects a node only when the identity or the target cloud asset resolves to an existing UAI asset, and the connection provides navigation and context for investigation without creating or modifying UAI assets.
The Cloud causality view provides the following connections for a node that resolves to a UAI asset:
Node name: The node displays the name recorded in the UAI, so the entity in the Cloud causality view matches the entity in the inventory.
Asset details: Selecting the node displays the UAI details for the asset in the left panel.
Asset card: Right-clicking the node and selecting the Open Asset Card action opens the asset card for the corresponding UAI asset.
For an issue, the identity and target cloud asset that resolve to UAI assets are recorded as the affected assets of the issue and link to the corresponding UAI assets.
Last updated
Was this helpful?
