Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
5 Days |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Low |
Description
A suspicious activity between different cloud projects.
Attacker's Goals
Abuse an existing connection and pivot through multiple projects to find their target.
Investigative actions
- Check if the identity intended to perform actions on the project.
- Check the operations that were performed on the project {caller_project}.
- Check if the identity performed additional operations in the cloud environment that might be malicious.
Variations
An identity with high administrative activity performed an unusual cross projects operationSuspicious cross projects activity