Cloud snapshot created or modified
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010), Collection (TA0009), Defense Impairment (TA0112)
ATT&CK Technique
Transfer Data to Cloud Account (T1537), Modify Cloud Compute Infrastructure (T1578), Data from Cloud Storage (T1530)
Severity
Informational
Description
A cloud identity has created or modified a cloud snapshot.
Attacker's Goals
Exfiltrate sensitive data that resides on the snapshot.
Investigative actions
Check if the identity intended to create or modify the snapshot.
Check if the identity performed additional malicious operations within the cloud environment.
Variations
Was this helpful?
