Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
SentinelOne Singularity XDR
FIN-218
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 08:57
Verified
What It Detects
A cloud-hosted asset (identified by having a cloud Instance ID in SentinelOne) lacks a Cloud Account ID, meaning it cannot be attributed to a specific AWS account, Azure subscription, or GCP project. Without account attribution, security teams cannot determine who owns or is responsible for this cloud workload, creating gaps in incident response and cloud governance.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Instance ID
not_empty
Cloud Account ID
is_empty
Remediation
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum