Hunting for signs of persistence in the cloud: an IR guide following the CircleCI incident
ID: 285ad6d3-19b6-54a6-9e1c-8aaeca927235
STIX ID: report--285ad6d3-19b6-54a6-9e1c-8aaeca927235
Feed Name: Wiz Blog
CircleCI disclosed a January 2023 security breach that exposed thousands of organizations' secrets; this report explains how attackers could leverage compromised cloud credentials to establish persistence across AWS, Azure, and GCP. It maps likely attacker TTPs (e.g., creating users/keys, updating function code, injecting startup scripts, creating service account keys), provides Athena/KQL/GCP logging queries to hunt for suspicious activity and known malicious IPs from the CircleCI incident, and lists remediation steps to remove backdoors and revoke malicious artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
