Cloud snapshot of a database or storage instance was publicly shared
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Exfiltration, Cloud Data Asset Public Exposure, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Medium
Description
A cloud identity has publicly shared a snapshot of a database or storage instance.
Attacker's Goals
Exfiltrate sensitive data that resides on the snapshot.
Investigative actions
Check if the identity intended to share the snapshot publicly.
Check if the identity performed additional malicious operations within the cloud environment.
Was this helpful?
