Fortinet white logo
Fortinet white logo

Alerts Reference

Suspicious Activity AWS User

Suspicious Activity AWS User

This alert occurs when Lacework FortiCNAPP detects suspicious activity related to one or more AWS identities, but with a lower confidence level than a Potentially Compromised AWS Keys alert. As with that more severe alert, if this suspicious activity corresponds to a genuine intrusion it is likely due to a leak or theft of AWS access keys.

Why this alert is important

This alert could represent an intrusion in its early stages where Lacework FortiCNAPP has not observed enough of the attacker’s activity to distinguish between that and background behaviors.

Investigation

See Investigation in Potentially Compromised AWS Keys.

Resolution

See Resolution in Potentially Compromised AWS Keys.

Suspicious Activity AWS User

Suspicious Activity AWS User

This alert occurs when Lacework FortiCNAPP detects suspicious activity related to one or more AWS identities, but with a lower confidence level than a Potentially Compromised AWS Keys alert. As with that more severe alert, if this suspicious activity corresponds to a genuine intrusion it is likely due to a leak or theft of AWS access keys.

Why this alert is important

This alert could represent an intrusion in its early stages where Lacework FortiCNAPP has not observed enough of the attacker’s activity to distinguish between that and background behaviors.

Investigation

See Investigation in Potentially Compromised AWS Keys.

Resolution

See Resolution in Potentially Compromised AWS Keys.