Techniques › T1537
T1537 Transfer Data to Cloud Account
exfiltration — IaaS, Office Suite, SaaS · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
6
Sigma rules tagged attack.t1537
0
KEV CVEs mapped here
<p>Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.</p><p>A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.</p><p>Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.</p><p>Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0573 Cross-Platform Detection of Data Transfer to Cloud Account v1.0
AN1580 IaaSDetects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.AWS:VPCFlowLogs
High volume internal-to-internal IP transfer or cross-account cloud transfer→ DC0085 Network Traffic ContentTunable:CrossAccountIDListRegionVolumeSizeThresholdGBTimeWindowAN1581 Office SuiteDetects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.Tunable:ExternalDomainListTimeWindowSharingMethodAN1582 SaaSDetects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.Tunable:UserContextDomainReputationListPayloadVolumeThreshold
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1537
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 04ad83ef-1a37-4c10-b57a-81092164bf33
Detects when a repository or an organization is being transferred to another location.
Author: Austin Songer @austinsonger
· 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 2b669496-d215-47d8-bd9a-f4a45bf07cda
Detects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
Author: Diogo Braz
· 2020-04-16 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
Author: Romain Gaillard (@romain-gaillard)
· 2024-07-29 · logsource: product=github service=audit · 69b3bd1e-b38a-462f-9a23-fbdbf63d2294
Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
Author: Austin Songer @austinsonger
· 2021-07-24 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 78b3756a-7804-4ef7-8555-7b9024a02e2d
Detects when a user tampers with S3 data management in Amazon Web Services.
Author: Darin Smith
· 2021-05-17 (modified 2021-08-19) · logsource: product=aws service=cloudtrail · abae8fec-57bd-4f87-aff6-6e3db989843d
Detects the modification of an EC2 snapshot's permissions to enable access from another account