kevmap

TechniquesT1537 › AN1580

AN1580 Analytic 1580

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.</p>
Detects
T1537 Transfer Data to Cloud Account
Part of
DET0573 Cross-Platform Detection of Data Transfer to Cloud Account

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailModifySnapshotAttributeDC0058 Snapshot Modification
AWS:CloudTrailPutBucketPolicyDC0023 Cloud Storage Modification
AWS:CloudTrailCreateSnapshotDC0057 Snapshot Creation
AWS:CloudTrailCopySnapshotDC0062 Snapshot Metadata
AWS:VPCFlowLogsHigh volume internal-to-internal IP transfer or cross-account cloud transferDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
CrossAccountIDListList of external cloud accounts authorized for snapshot or bucket sharing
RegionGeographic region in which the sharing occurs (may impact logging availability)
VolumeSizeThresholdGBThreshold to alert on snapshot size or object volume
TimeWindowTemporal window between snapshot creation and external sharing