kevmap

Techniques › T1537

T1537 Transfer Data to Cloud Account

exfiltration — IaaS, Office Suite, SaaS · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
6
Sigma rules tagged attack.t1537
0
KEV CVEs mapped here
<p>Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.</p><p>A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.</p><p>Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.</p><p>Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1537

Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 04ad83ef-1a37-4c10-b57a-81092164bf33
Detects when a repository or an organization is being transferred to another location.
Techniques: T1020T1537
Author: Austin Songer @austinsonger · 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_management · 2b669496-d215-47d8-bd9a-f4a45bf07cda
Detects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
Techniques: T1537
Author: Diogo Braz · 2020-04-16 (modified 2022-10-05) · logsource: product=aws service=cloudtrail · 54b9a76a-3c71-4673-b4b3-2edb4566ea7b
An attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
Techniques: T1005T1537
Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 69b3bd1e-b38a-462f-9a23-fbdbf63d2294
Detects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
Techniques: T1020T1537
Author: Austin Songer @austinsonger · 2021-07-24 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 78b3756a-7804-4ef7-8555-7b9024a02e2d
Detects when a user tampers with S3 data management in Amazon Web Services.
Techniques: T1537
Author: Darin Smith · 2021-05-17 (modified 2021-08-19) · logsource: product=aws service=cloudtrail · abae8fec-57bd-4f87-aff6-6e3db989843d
Detects the modification of an EC2 snapshot's permissions to enable access from another account
Techniques: T1537