Techniques › T1537 › AN1580
AN1580 Analytic 1580
IaaS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.</p>
- Detects
- T1537 Transfer Data to Cloud Account
- Part of
- DET0573 Cross-Platform Detection of Data Transfer to Cloud Account
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| AWS:CloudTrail | ModifySnapshotAttribute | DC0058 Snapshot Modification |
| AWS:CloudTrail | PutBucketPolicy | DC0023 Cloud Storage Modification |
| AWS:CloudTrail | CreateSnapshot | DC0057 Snapshot Creation |
| AWS:CloudTrail | CopySnapshot | DC0062 Snapshot Metadata |
| AWS:VPCFlowLogs | High volume internal-to-internal IP transfer or cross-account cloud transfer | DC0085 Network Traffic Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
CrossAccountIDList | List of external cloud accounts authorized for snapshot or bucket sharing |
Region | Geographic region in which the sharing occurs (may impact logging availability) |
VolumeSizeThresholdGB | Threshold to alert on snapshot size or object volume |
TimeWindow | Temporal window between snapshot creation and external sharing |