{"id":"T1537","name":"Transfer Data to Cloud Account","url":"https://attack.mitre.org/techniques/T1537","tactics":["exfiltration"],"platforms":["IaaS","Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0573","stix_id":"x-mitre-detection-strategy--22a31282-d190-449b-a102-2d562f906b7d","name":"Cross-Platform Detection of Data Transfer to Cloud Account","url":"https://attack.mitre.org/detectionstrategies/DET0573","analytics":[{"id":"AN1580","stix_id":"x-mitre-analytic--383dda28-1d76-4605-a53d-07829f3d7ef8","name":"Analytic 1580","description":"Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.","url":"https://attack.mitre.org/detectionstrategies/DET0573#AN1580","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"ModifySnapshotAttribute","data_component":"DC0058","data_component_name":"Snapshot Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"PutBucketPolicy","data_component":"DC0023","data_component_name":"Cloud Storage Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"CreateSnapshot","data_component":"DC0057","data_component_name":"Snapshot Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"CopySnapshot","data_component":"DC0062","data_component_name":"Snapshot Metadata","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"High volume internal-to-internal IP transfer or cross-account cloud transfer","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"aws-vpcflowlogs"}],"mutable_elements":[{"field":"CrossAccountIDList","description":"List of external cloud accounts authorized for snapshot or bucket sharing"},{"field":"Region","description":"Geographic region in which the sharing occurs (may impact logging availability)"},{"field":"VolumeSizeThresholdGB","description":"Threshold to alert on snapshot size or object volume"},{"field":"TimeWindow","description":"Temporal window between snapshot creation and external sharing"}],"live":true,"detection_strategies":["DET0573"],"techniques":["T1537"]},{"id":"AN1581","stix_id":"x-mitre-analytic--60b2d6f4-1bf0-4c52-8923-ac8e3b8088d4","name":"Analytic 1581","description":"Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.","url":"https://attack.mitre.org/detectionstrategies/DET0573#AN1581","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"SharingSet","data_component":"DC0023","data_component_name":"Cloud Storage Modification","log_source_slug":"m365-unified"},{"name":"m365:unified","channel":"AnonymousLinkCreated","data_component":"DC0027","data_component_name":"Cloud Storage Metadata","log_source_slug":"m365-unified"},{"name":"m365:unified","channel":"FileAccessed","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"ExternalDomainList","description":"Known partner or adversarial cloud identities/domains"},{"field":"TimeWindow","description":"Duration between file access and external sharing"},{"field":"SharingMethod","description":"Type of link (anonymous, internal, organization-wide) to alert on"}],"live":true,"detection_strategies":["DET0573"],"techniques":["T1537"]},{"id":"AN1582","stix_id":"x-mitre-analytic--d1ef9a86-7781-4b9e-9178-c2e5b1782c1f","name":"Analytic 1582","description":"Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.","url":"https://attack.mitre.org/detectionstrategies/DET0573#AN1582","platforms":["SaaS"],"log_source_references":[{"name":"saas:googledrive","channel":"drive.permission.add","data_component":"DC0023","data_component_name":"Cloud Storage Modification","log_source_slug":"saas-googledrive"},{"name":"saas:box","channel":"collaboration.invite","data_component":"DC0027","data_component_name":"Cloud Storage Metadata","log_source_slug":"saas-box"}],"mutable_elements":[{"field":"UserContext","description":"Whether the user is in a high-privileged or VIP group"},{"field":"DomainReputationList","description":"Allowlist or blocklist of external SaaS domains"},{"field":"PayloadVolumeThreshold","description":"Size or number of shared files triggering alert"}],"live":true,"detection_strategies":["DET0573"],"techniques":["T1537"]}],"live":true,"version":"1.0","techniques":["T1537"]}],"sigma_rules":[{"id":"04ad83ef-1a37-4c10-b57a-81092164bf33","title":"Github Repository/Organization Transferred","author":"Romain Gaillard (@romain-gaillard)","status":"test","level":"medium","date":"2024-07-29","modified":null,"description":"Detects when a repository or an organization is being transferred to another location.","references":["https://docs.github.com/en/repositories/creating-and-managing-repositories/transferring-a-repository","https://docs.github.com/en/organizations/managing-organization-settings/transferring-organization-ownership","https://docs.github.com/en/migrations","https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise#migration"],"logsource":{"product":"github","service":"audit"},"tags":["attack.persistence","attack.exfiltration","attack.t1020","attack.t1537"],"path":"rules/application/github/audit/github_repo_or_org_transferred.yml","techniques":["T1020","T1537"],"cves":[]},{"id":"2b669496-d215-47d8-bd9a-f4a45bf07cda","title":"Data Exfiltration to Unsanctioned Apps","author":"Austin Songer @austinsonger","status":"test","level":"medium","date":"2021-08-23","modified":"2022-10-09","description":"Detects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.","references":["https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy","https://learn.microsoft.com/en-us/defender-cloud-apps/policy-template-reference"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.exfiltration","attack.t1537"],"path":"rules/cloud/m365/threat_management/microsoft365_data_exfiltration_to_unsanctioned_app.yml","techniques":["T1537"],"cves":[]},{"id":"54b9a76a-3c71-4673-b4b3-2edb4566ea7b","title":"AWS EC2 VM Export Failure","author":"Diogo Braz","status":"test","level":"low","date":"2020-04-16","modified":"2022-10-05","description":"An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.","references":["https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport.html#export-instance"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.collection","attack.t1005","attack.exfiltration","attack.t1537"],"path":"rules/cloud/aws/cloudtrail/aws_ec2_vm_export_failure.yml","techniques":["T1005","T1537"],"cves":[]},{"id":"69b3bd1e-b38a-462f-9a23-fbdbf63d2294","title":"Github Fork Private Repositories Setting Enabled/Cleared","author":"Romain Gaillard (@romain-gaillard)","status":"test","level":"medium","date":"2024-07-29","modified":null,"description":"Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).\n","references":["https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/audit-log-events-for-your-enterprise#private_repository_forking"],"logsource":{"product":"github","service":"audit"},"tags":["attack.persistence","attack.exfiltration","attack.t1020","attack.t1537"],"path":"rules/application/github/audit/github_fork_private_repos_enabled_or_cleared.yml","techniques":["T1020","T1537"],"cves":[]},{"id":"78b3756a-7804-4ef7-8555-7b9024a02e2d","title":"AWS S3 Data Management Tampering","author":"Austin Songer @austinsonger","status":"test","level":"low","date":"2021-07-24","modified":"2022-10-09","description":"Detects when a user tampers with S3 data management in Amazon Web Services.","references":["https://github.com/elastic/detection-rules/pull/1145/files","https://docs.aws.amazon.com/AmazonS3/latest/API/API_Operations.html","https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketLogging.html","https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketWebsite.html","https://docs.aws.amazon.com/AmazonS3/latest/API/API_PutBucketEncryption.html","https://docs.aws.amazon.com/AmazonS3/latest/userguide/setting-repl-config-perm-overview.html","https://docs.aws.amazon.com/AmazonS3/latest/API/API_RestoreObject.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.exfiltration","attack.t1537"],"path":"rules/cloud/aws/cloudtrail/aws_s3_data_management_tampering.yml","techniques":["T1537"],"cves":[]},{"id":"abae8fec-57bd-4f87-aff6-6e3db989843d","title":"AWS Snapshot Backup Exfiltration","author":"Darin Smith","status":"test","level":"medium","date":"2021-05-17","modified":"2021-08-19","description":"Detects the modification of an EC2 snapshot's permissions to enable access from another account","references":["https://www.justice.gov/file/1080281/download"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.exfiltration","attack.t1537"],"path":"rules/cloud/aws/cloudtrail/aws_snapshot_backup_exfiltration.yml","techniques":["T1537"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}