Suspicious EBS snapshots deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Inhibit System Recovery (T1490)
Severity
Low
Description
An identity deleted multiple EBS snapshots from the project, considerably more than usual.
Attacker's Goals
Adversaries may delete data to prevent the recovery of a corrupted system.
Investigative actions
Identify the deleted snapshots and their associated resources.
Investigate the identity that performed the deletion and review recent related activity.
Variations
PreviousSuspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin
NextSuspicious Encrypting File System Remote call (EFSRPC) to domain controller
Was this helpful?
