Uber Cybersecurity Incident: Which Logs Do IR Teams Need to Focus On?
ID: 25ed827f-2d63-540b-a73a-9f1755a20446
STIX ID: report--25ed827f-2d63-540b-a73a-9f1755a20446
Feed Name: Mitiga
On September 16 Uber disclosed a major compromise where an attacker leveraged phishing to obtain admin credentials and pivoted across multiple services (Thycotic PAM, AWS, Google Workspace, HackerOne, Slack). The report enumerates the relevant audit and activity logs investigators should collect from each platform (Thycotic audit reports, AWS CloudTrail, Google Reports API, HackerOne and Slack audit logs) to trace actions, detect anomalous privileged behavior, and recommends a holistic breach readiness approach including forensic data lakes and SaaS/cloud-focused IR partnerships.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
