AWS EBS enumeration activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Cloud Infrastructure Discovery (T1580), Cloud Service Discovery (T1526)
Severity
Informational
Description
EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance.
Attacker's Goals
Identify existing EBS volumes and snapshots to understand what storage resources are available and in use.
Assess if snapshots are shared with other accounts or publicly accessible.
Identify potential data exfiltration paths or targets.
Investigative actions
Review which EBS API calls were executed and their frequency.
Analyze the identity performing the actions.
Inspect sharing or access configurations of enumerated snapshots.
Was this helpful?
