Cross-source coverage

T1537 / ATT&CK

Transfer Data to Cloud Account

49 rules across 7 sources.

2 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.

A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.

Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.

Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.

Tactics
Exfiltration
Platforms
IaaS · Office Suite · SaaS
Telemetry
AWS:CloudTrailAWS:VPCFlowLogsm365:unifiedsaas:googledrivesaas:box

How MITRE says to detect it DET0573

Cross-Platform Detection of Data Transfer to Cloud Account

IaaS Analytic 1580

Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.

  • AWS:CloudTrail ModifySnapshotAttribute
  • AWS:CloudTrail PutBucketPolicy
  • AWS:CloudTrail CreateSnapshot
  • AWS:CloudTrail CopySnapshot
  • AWS:VPCFlowLogs High volume internal-to-internal IP transfer or cross-account cloud transfer

Office Suite Analytic 1581

Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.

  • m365:unified SharingSet
  • m365:unified AnonymousLinkCreated
  • m365:unified FileAccessed

SaaS Analytic 1582

Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.

  • saas:googledrive drive.permission.add
  • saas:box collaboration.invite

elastic/detection-rules

14 rules
Detection Severity Format
AWS EC2 AMI Shared with Another Account High Elastic TOML
AWS S3 Bucket Replicated to Another Account High Elastic TOML
AWS EC2 EBS Snapshot Shared or Made Public Medium Elastic TOML
AWS EC2 Export Task Medium Elastic TOML
AWS EC2 Full Network Packet Capture Detected Medium Elastic TOML
AWS ECR Repository or Registry Policy Granted Public Access Medium Elastic TOML
AWS RDS DB Snapshot Shared with Another Account Medium Elastic TOML
AWS S3 Bucket Policy Added to Allow Public Access Medium Elastic TOML
AWS S3 Bucket Policy Added to Share with External Account Medium Elastic TOML
Google Workspace Drive Data Transfer or Takeout Export Initiated Medium Elastic TOML

+ 4 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

14 rules
Detection Severity Format
AWS RDS Snapshot Exported to S3 High Panther Python
AWS RDS Snapshot Shared High Panther Python
AWS S3 Object Exfiltration WITH Object Deletion High Panther Python
Amazon Machine Image (AMI) Modified to Allow Public Access Medium Panther Python
AppOmni Alert Passthrough Medium Panther Python
AWS RDS Snapshot Copied Cross-Region Medium Panther Python
AWS Resource Made Public Medium Panther Python
AWS S3 Object Copied to External Account Bucket Medium Panther Python
AWS Snapshot Made Public Medium Panther Python
GCP GCS Bulk Object Rewrite Operation Medium Panther Python

+ 4 more from panther-labs/panther-analysis → showing the 10 highest-severity

splunk/security_content

7 rules
Detection Severity Format
ASL AWS EC2 Snapshot Shared Externally Undefined SPL
AWS AMI Attribute Modification for Exfiltration Undefined SPL
AWS EC2 Snapshot Shared Externally Undefined SPL
AWS Exfiltration via Bucket Replication Undefined SPL
AWS Exfiltration via EC2 Snapshot Undefined SPL
AWS S3 Exfiltration Behavior Identified Undefined SPL
High Frequency Copy Of Files In Network Share Undefined SPL

SigmaHQ/sigma

6 rules
Detection Severity Format
AWS Snapshot Backup Exfiltration Medium Sigma
Data Exfiltration to Unsanctioned Apps Medium Sigma
Github Fork Private Repositories Setting Enabled/Cleared Medium Sigma
Github Repository/Organization Transferred Medium Sigma
AWS EC2 VM Export Failure Low Sigma
AWS S3 Data Management Tampering Low Sigma

chronicle/detection-rules

4 rules
Detection Severity Format
aws_ec2_ami_or_snapshot_shared_publicly High YARA-L
aws_rds_snapshot_shared_publicly High YARA-L
gcp_gce_image_open_to_public High YARA-L
github_outgoing_organization_transfer_initiated Low YARA-L

Azure/Azure-Sentinel

3 rules
Detection Severity Format
Azure Storage File Create, Access, Delete Undefined KQL
Azure Storage File Create and Delete Undefined KQL
GitHub OAuth App Restrictions Disabled Undefined KQL

Wazuh Core Ruleset

1 rule
Detection Severity Format
GCP logging sink modified. Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.