Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
N/A (single event) |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
Cloud |
Detector Tags |
Cloud Data Asset Exfiltration |
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Informational |
Description
An identity accessed a backup cloud storage.
Attacker's Goals
Exfiltrate data from the cloud environment.
Investigative actions
Check the identity which invoked the operation.
Check the accessed resource and verify it doesn't contain sensitive data.