For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS Transfer Family server created

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Data Detection & Response

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Informational

Description

A cloud identity created server using AWS Transfer Family service.

Attacker's Goals

  • Attacker is trying to exfiltrate data out of AWS storage services.

Investigative actions

  • Check if the AWS Transfer Family service is used by your organization.

  • Check if {identity_name} created a server using this service before.

  • Check which storage instances were affected by {transfer_server_id} server.

Variations

Unusual cloud transfer service activity

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010)

ATT&CK Technique

Transfer Data to Cloud Account (T1537)

Severity

Low

Description

A cloud identity created server using AWS Transfer Family service.

Attacker's Goals

  • Attacker is trying to exfiltrate data out of AWS storage services.

Investigative actions

  • Check if {identity_name} was involved in additional suspicious activity.

  • Check which storage instances were affected by {transfer_server_id} server.

Was this helpful?