AWSCloudTrail - Activity in unused or unsupported cloud regions

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies AWS API activity in regions not historically used by the account, which may indicate defense evasion or unauthorized access from a compromised identity.

Attribute Value
Type Hunting Query
Solution Amazon Web Services
ID e0d57543-acbd-428b-bb96-24a67506f84d
Severity Medium
Tactics DefenseEvasion
Techniques T1535
Required Connectors AWS, AWSS3
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AWSCloudTrail

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Amazon Web Services