EC2 instance Amazon machine image was created
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Informational
Description
Amazon machine image was created from elastic compute cloud instance.
Attacker's Goals
Creating Amazon machine images might be part of elastic compute cloud instance exfiltration chain.
Investigative actions
Check if {identity_name} to create Amazon machine image.
Check if the {cloud_aws_instance_id} instance did not contain any sensitive data.
PreviousEC2 backdoor created with newly added external SSH or RDP access
NextElevation to SYSTEM via services
Was this helpful?
