mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.6 KiB
1.6 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | |||||
|---|---|---|---|---|---|---|---|---|
| Suspicious Cloud Instance Activities | 2020-08-25 | true |
|
Description
Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment.
- ID: 8168ca88-392e-42f4-85a2-767579c660ce
- Product: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Change
- Last Updated: 2020-08-25
- Author: David Dorsey, Splunk
Detection profiles
| Name | Technique | Type |
|---|---|---|
| Abnormally High Number Of Cloud Instances Destroyed | None | Anomaly |
| Abnormally High Number Of Cloud Instances Launched | None | Anomaly |
| Cloud Instance Modified By Previously Unseen User | None | Anomaly |
| Detect shared ec2 snapshot | None | TTP |
Reference
source | version: 1