Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
10 Minutes |
Deduplication Period |
5 Days |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
An identity performed multiple actions that were denied, which may indicate it is being misused.
Attacker's Goals
Execute various commands to explore the cloud environment.
Investigative actions
Check if the API calls were made by the identity.
Check if there are additional calls executed by the identity.