Product
high
advisory
Cross-Environment Secret Harvesting via Cloud APIs
1 TTPAdversaries are utilizing compromised credentials and stolen session tokens to perform rapid, automated secret harvesting across AWS, GCP, Azure, and Kubernetes environments from singular source IP addresses.
AWS Secrets Manager +3
credential-access
cloud
identity-theft
1t
high
advisory
Multiple Cloud Secrets Accessed by Source Address
2 rules 1 TTPA single source IP accessing secret-management APIs across multiple cloud providers (AWS, GCP, Azure) and Kubernetes clusters within a short timeframe indicates credential theft or token replay for secret harvesting.
AWS Secrets Manager +3
cloud
credential-access
kubernetes
2r
1t