kevmap

TechniquesT1486 › AN0606

AN0606 Analytic 0606

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.</p>
Detects
T1486 Data Encrypted for Impact
Part of
DET0215 Detection of Multi-Platform File Encryption for Impact

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailPutObject (with SSE-C), UploadPart (SSE-C)DC0023 Cloud Storage Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
SSEHeaderSSE-C headers indicate attacker-controlled encryption keys.
AffectedBucketPrioritize logs, backups, or shared document storage buckets.
UserAgentDetect scripted automation vs console-based API behavior.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2015-8651Adobe Flash PlayerMapped
CVE-2016-1019Adobe Flash PlayerMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-42258BQE BillQuick Web SuiteMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-45046Apache Log4j2Mapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2023-38831RARLAB WinRARMapped