An AWS EC2 instance containing sensitive data was exported
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Stealth Tactics, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data.
Attacker's Goals
An attack may exfiltrate data from an EC2 instance to an S3 bucket outside the account.
Investigative actions
Check the identity that exported the instance.
Check to which S3 bucket the EC2 was exported into.
Check the S3 bucket permission and policy.
PreviousAn AWS database service master user password was changed
NextAn AWS EC2 instance was exported from a production account
Was this helpful?
