Hackers Abuse Cloud Logging Services to Evade Detection and Defender’s Visibility
ID: 10f76a8d-67ed-56de-b9ee-6fd11f0c0868
STIX ID: report--10f76a8d-67ed-56de-b9ee-6fd11f0c0868
Feed Name: cybersecurityNews.com
Palo Alto Networks Unit 42 warns that adversaries are targeting cloud logging services (e.g., AWS CloudTrail, Google Cloud logging) to create blind spots and gain long-term visibility by stopping or tampering with log collection, deleting log stores, replacing encryption keys, poisoning log files, or redirecting log streams to attacker-controlled destinations; the report explains impacts (loss of visibility, covert persistence, potential exfiltration) and recommends restricting critical logging permissions, enabling log integrity features, and treating log pipelines as critical assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
