Product
Storm-3168 Cloud Attack Campaign
1 rule 3 TTPsStorm-3168 (linked to JADEPUFFER) leverages compromised Azure service principals to execute automated resource destruction and credential exfiltration through AI-orchestrated cloud API manipulation.
Cross-Environment Secret Harvesting via Cloud APIs
1 TTPAdversaries are utilizing compromised credentials and stolen session tokens to perform rapid, automated secret harvesting across AWS, GCP, Azure, and Kubernetes environments from singular source IP addresses.
Azure Key Vault Excessive Secret or Key Retrieval
2 rules 2 TTPsDetects excessive secret or key retrieval operations from Azure Key Vault, indicating potential unauthorized access attempts or credential harvesting.
Multiple Cloud Secrets Accessed by Source Address
2 rules 1 TTPA single source IP accessing secret-management APIs across multiple cloud providers (AWS, GCP, Azure) and Kubernetes clusters within a short timeframe indicates credential theft or token replay for secret harvesting.
Azure Key Vault Unusual Secret Key Usage
2 rules 1 TTPDetects unusual secret, key, or certificate retrieval operations from Azure Key Vault by a user principal that has not been seen previously, potentially indicating unauthorized access attempts.
Azure Key Vault Modified by Unusual User
2 rules 2 TTPsThis rule identifies modifications to Azure Key Vaults by unusual users, potentially leading to data breaches or service disruptions through defense evasion or impact operations.