> For the complete documentation index, see [llms.txt](https://help.datadefender.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.datadefender.io/how-it-works/portal-overview/data-security-insights/suspected-attacks.md).

# Suspected Attacks

AI detection of suspicious event sequences.

The Suspected Attacks page uses AI-assisted detection to identify and surface potential sequences of suspicious events across your cloud environment that together indicate a possible breach or attack in progress.

<figure><img src="https://3802454275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FobDf5vJfItiNrkno1uJc%2Fuploads%2FmbWiy8JenWWyjYi4lQmA%2Fimage.png?alt=media&amp;token=37465971-74db-48ef-9b90-854602240a9e" alt=""><figcaption></figcaption></figure>

***

### What Is an Attack Chain?

An attack chain is a series of correlated events that suggest an attempt or successful data compromise. DataDefender maps detected events against MITRE ATT\&CK techniques and groups related events into a single chain so you can see the full picture of an attack rather than individual alerts.

***

### Status Filter

Use the status filter buttons to narrow down the attack chains by their current state:

| Status                  | Meaning                                              |
| ----------------------- | ---------------------------------------------------- |
| **All**                 | Show every detected chain                            |
| **Attacks**             | Categorizes single activities that indicate attacks  |
| **Multi-Stage Attacks** | Categorizes multi-stage events that indicate attacks |

The count next to each button shows how many chains are in that state. Click on a specific type of attack to see an icon-based view of potential threats.

<figure><img src="https://3802454275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FobDf5vJfItiNrkno1uJc%2Fuploads%2FrsHgSoIh99WrQ4g1TS2h%2Fimage.png?alt=media&amp;token=de871d80-18a0-40fc-a006-0c613fb48c6a" alt=""><figcaption></figcaption></figure>

***

### Filtering and Sorting

**Filtering:** Select the time zone and severity. Click 'More Filters' to access more granular controls like Account ID, Location, and more. You can also add filters to search for specific attacks.

**Sort:** Use the sort dropdown to change the ordering (e.g. by date, severity, or completion). Use the arrow button next to it to toggle between ascending and descending order.

<figure><img src="https://3802454275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FobDf5vJfItiNrkno1uJc%2Fuploads%2FwTRFB4i4k3KrZdKgr8la%2Fimage.png?alt=media&amp;token=3a0ec9cb-f043-4f93-9cac-11998c999f9a" alt=""><figcaption></figcaption></figure>

***

### Attack Chain Cards

Each card in the list represents one detected attack chain. Cards show:

* Scenario name and description
* Current status badge (Occurred / Attempted / Blocked / Incomplete)
* Date of first and last detected activity

Click a card to expand it and see the full attack details, including:

* **Summary:** Brief summary of attack and outcome
* **Affected resources:** Which storage resources were involved
* **Threat Category:** Type of threat (Access Control, Data Exfiltration, etc.)
* **Threat State:** Current threat level of the finding

<figure><img src="https://3802454275-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FobDf5vJfItiNrkno1uJc%2Fuploads%2F91BrcsOs5yzvXDyG1Awr%2Fimage.png?alt=media&amp;token=448e57cb-b90f-4217-a005-d2f34992bf39" alt=""><figcaption></figcaption></figure>

***

### Pagination

Use the **Previous** and **Next** buttons to navigate through the list of attack chains.

***

### Related Pages

* [Security Holes](/how-it-works/portal-overview/data-security-insights/security-holes.md): See the misconfigurations that may enable attacks
* [Forensic Analysis](/how-it-works/portal-overview/supporting-information/forensic-analysis.md): Search raw CloudTrail logs for specific events
  * Consider checking [File Access by User](/how-it-works/portal-overview/supporting-information/forensic-analysis.md#file-access-by-user) to investigate which files were accessed by certain identities during a potential attack
