A cloud snapshot of AWS database or storage was modified or shared
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
A cloud identity has shared a snapshot of an AWS database or storage instance.
Attacker's Goals
Exfiltrate sensitive data that resides on the snapshot.
Investigative actions
Check if the identity intended to modify the snapshot.
Check if the identity performed additional malicious operations within the cloud environment.
Variations
Was this helpful?
