{"id":"T1530","name":"Data from Cloud Storage","url":"https://attack.mitre.org/techniques/T1530","tactics":["collection"],"platforms":["IaaS","Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0484","stix_id":"x-mitre-detection-strategy--1177cbb7-bc00-4a36-8774-d51b7b3c66e9","name":"Multi-Platform Cloud Storage Exfiltration Behavior Chain","url":"https://attack.mitre.org/detectionstrategies/DET0484","analytics":[{"id":"AN1328","stix_id":"x-mitre-analytic--d9a1ace1-6307-4db7-925f-67057361e66a","name":"Analytic 1328","description":"Spike in object access from new IAM user or role followed by data exfiltration to external IPs","url":"https://attack.mitre.org/detectionstrategies/DET0484#AN1328","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"GetObject, CopyObject","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"AssumeRole","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"Unusual volume of data transferred from S3 storage endpoints to non-corporate IPs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"aws-vpcflowlogs"}],"mutable_elements":[{"field":"TimeWindow","description":"Timeframe for data transfer correlation (e.g., 10 minutes)"},{"field":"ExternalIPAllowList","description":"Known list of corporate and expected outbound IP addresses"}],"live":true,"detection_strategies":["DET0484"],"techniques":["T1530"]},{"id":"AN1329","stix_id":"x-mitre-analytic--8226ce94-1f5b-4ab0-b0bc-92f1d225eaa4","name":"Analytic 1329","description":"OAuth token granted to external app followed by download of high-volume files in OneDrive/Google Drive","url":"https://attack.mitre.org/detectionstrategies/DET0484#AN1329","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"FileAccessed, FileDownloaded, ConsentGranted","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"AppRegistrationNamePattern","description":"Pattern of suspicious OAuth app names (e.g., `rclone`, `mega`, `backup*`)"},{"field":"DownloadThresholdMB","description":"Flag file downloads over X MB (e.g., >100MB) within short intervals"}],"live":true,"detection_strategies":["DET0484"],"techniques":["T1530"]},{"id":"AN1330","stix_id":"x-mitre-analytic--4eca5ae6-797c-41cb-bacd-dc7a6da58fb0","name":"Analytic 1330","description":"Internal user account accesses shared links outside org followed by mass file download","url":"https://attack.mitre.org/detectionstrategies/DET0484#AN1330","platforms":["Office Suite"],"log_source_references":[{"name":"m365:sharepoint","channel":"AnonymousLinkCreated, FileDownloaded","data_component":"DC0025","data_component_name":"Cloud Storage Access","log_source_slug":"m365-sharepoint"},{"name":"azure:signinlogs","channel":"SigninSuccess","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"LinkVisibilityScope","description":"Whether links allow anonymous/external access"},{"field":"DownloadBurstThreshold","description":"# of files downloaded within <5 mins (e.g., >50 files)"}],"live":true,"detection_strategies":["DET0484"],"techniques":["T1530"]}],"live":true,"version":"1.0","techniques":["T1530"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2024-49035","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-22952","state":"stale","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}