Cross-source coverage
T1537 / ATT&CK
Transfer Data to Cloud Account
51 rules across 7 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
A defender who is monitoring for large transfers to outside the cloud environment through normal file transfers or over command and control channels may not be watching for data transfers to another account within the same cloud provider. Such transfers may utilize existing cloud provider APIs and the internal address space of the cloud provider to blend into normal traffic or avoid data transfers over external network interfaces.
Adversaries may also use cloud-native mechanisms to share victim data with adversary-controlled cloud accounts, such as creating anonymous file sharing links or, in Azure, a shared access signature (SAS) URI.
Incidents have been observed where adversaries have created backups of cloud instances and transferred them to separate accounts.
- Tactics
- Exfiltration
- Platforms
- IaaS · Office Suite · SaaS
- Telemetry
-
AWS:CloudTrailAWS:VPCFlowLogsm365:unifiedsaas:googledrivesaas:box
How MITRE says to detect it DET0573
Cross-Platform Detection of Data Transfer to Cloud Account
IaaS Analytic 1580
Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.
AWS:CloudTrailModifySnapshotAttributeAWS:CloudTrailPutBucketPolicyAWS:CloudTrailCreateSnapshotAWS:CloudTrailCopySnapshotAWS:VPCFlowLogsHigh volume internal-to-internal IP transfer or cross-account cloud transfer
Office Suite Analytic 1581
Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.
m365:unifiedSharingSetm365:unifiedAnonymousLinkCreatedm365:unifiedFileAccessed
SaaS Analytic 1582
Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.
saas:googledrivedrive.permission.addsaas:boxcollaboration.invite
elastic/detection-rules
16 rules| Detection | Severity | Format |
|---|---|---|
| AWS EC2 AMI Shared with Another Account | High | Elastic TOML |
| AWS S3 Bucket Replicated to Another Account | High | Elastic TOML |
| AWS EC2 EBS Snapshot Shared or Made Public | Medium | Elastic TOML |
| AWS EC2 Export Task | Medium | Elastic TOML |
| AWS EC2 Full Network Packet Capture Detected | Medium | Elastic TOML |
| AWS ECR Repository or Registry Policy Granted Public Access | Medium | Elastic TOML |
| AWS RDS DB Snapshot Shared with Another Account | Medium | Elastic TOML |
| AWS S3 Bucket Policy Added to Allow Public Access | Medium | Elastic TOML |
| AWS S3 Bucket Policy Added to Share with External Account | Medium | Elastic TOML |
| Deprecated - AWS EC2 Snapshot Activity | Medium | Elastic TOML |
+ 6 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
14 rules| Detection | Severity | Format |
|---|---|---|
| AWS RDS Snapshot Exported to S3 | High | Panther Python |
| AWS RDS Snapshot Shared | High | Panther Python |
| AWS S3 Object Exfiltration WITH Object Deletion | High | Panther Python |
| Amazon Machine Image (AMI) Modified to Allow Public Access | Medium | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| AWS RDS Snapshot Copied Cross-Region | Medium | Panther Python |
| AWS Resource Made Public | Medium | Panther Python |
| AWS S3 Object Copied to External Account Bucket | Medium | Panther Python |
| AWS Snapshot Made Public | Medium | Panther Python |
| GCP GCS Bulk Object Rewrite Operation | Medium | Panther Python |
+ 4 more from panther-labs/panther-analysis → showing the 10 highest-severity
splunk/security_content
7 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS EC2 Snapshot Shared Externally | Undefined | SPL |
| AWS AMI Attribute Modification for Exfiltration | Undefined | SPL |
| AWS EC2 Snapshot Shared Externally | Undefined | SPL |
| AWS Exfiltration via Bucket Replication | Undefined | SPL |
| AWS Exfiltration via EC2 Snapshot | Undefined | SPL |
| AWS S3 Exfiltration Behavior Identified | Undefined | SPL |
| High Frequency Copy Of Files In Network Share | Undefined | SPL |
SigmaHQ/sigma
6 rules| Detection | Severity | Format |
|---|---|---|
| AWS Snapshot Backup Exfiltration | Medium | Sigma |
| Data Exfiltration to Unsanctioned Apps | Medium | Sigma |
| Github Fork Private Repositories Setting Enabled/Cleared | Medium | Sigma |
| Github Repository/Organization Transferred | Medium | Sigma |
| AWS EC2 VM Export Failure | Low | Sigma |
| AWS S3 Data Management Tampering | Low | Sigma |
chronicle/detection-rules
4 rules| Detection | Severity | Format |
|---|---|---|
| aws_ec2_ami_or_snapshot_shared_publicly | High | YARA-L |
| aws_rds_snapshot_shared_publicly | High | YARA-L |
| gcp_gce_image_open_to_public | High | YARA-L |
| github_outgoing_organization_transfer_initiated | Low | YARA-L |
Azure/Azure-Sentinel
3 rules| Detection | Severity | Format |
|---|---|---|
| Azure Storage File Create, Access, Delete | Undefined | KQL |
| Azure Storage File Create and Delete | Undefined | KQL |
| GitHub OAuth App Restrictions Disabled | Undefined | KQL |
Wazuh Core Ruleset
1 rule| Detection | Severity | Format |
|---|---|---|
| GCP logging sink modified. | Low | Wazuh XML |