Detections
- Home
- - Detections
- -DT102
- ID: DT102
- Created: 13th September 2024
- Updated: 13th September 2024
- Contributor: Ismael Briones-Vilar
Cloud User and Entity Behavior Analytics (UEBA)
Deploy UEBA solutions designed for cloud environments to monitor and analyze the behavior of users, applications, network devices, servers, and endpoints accessing cloud resources. Cloud UEBA systems track normal behavior patterns and detect anomalies that could indicate potential security risks. For instance, they can identify when a user or entity is downloading unusually large volumes of data, accessing an excessive number of resources, or engaging in data transfers that deviate from their usual behavior.
Sections
ID | Name | Description |
---|---|---|
IF002.010 | Exfiltration via Bring Your Own Device (BYOD) | A subject connects their personal device, under a Bring Your Own Device (BYOD) policy, to organization resources, such as on-premises systems or cloud-based platforms. By leveraging this access, the subject exfiltrates sensitive or confidential data. This unauthorized data transfer can occur through various means, including copying files to the personal device, sending data via email, or using cloud storage services. |
AF018.002 | Environment Tripwires | The subject develops a custom API that monitors specific activities, network traffic, and system changes within the target environment. The API could monitor HTTP/HTTPS requests directed at sensitive endpoints, track modifications to security group settings (such as firewalls or access policies), and identify administrative actions like changes to user accounts, data access requests, or logging configurations.
This tripwire API is embedded within various parts of the environment:
Once deployed, the tripwire API continuously monitors network traffic, API calls, and system changes for indicators of an investigation. It looks for:
The API can use whitelists for expected IP addresses or user accounts, triggering alerts if unexpected access occurs.
Upon detecting activity, the API tripwire can take immediate evasive actions:
|