An AWS EC2 instance was exported into an unknown S3 bucket
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Stealth Tactics, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
An EC2 instance was exported to an unknown S3 bucket.
Attacker's Goals
An attack may exfiltrate data from an EC2 instance to an S3 bucket outside the account.
Investigative actions
Check the identity that exported the instance.
Check to which S3 bucket the EC2 was exported into.
Check the S3 bucket permission and policy.
PreviousAn AWS EC2 instance was exported from a production account
NextAn AWS EFS File-share mount was deleted
Was this helpful?
