Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0010 ✕
Download CSV Show ATT&CK heatmapA cloud snapshot of AWS database or storage was modified or shared Informational Cloud 2 variations
A cloud identity has shared a snapshot of an AWS database or storage instance.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Exfiltration (TA0010)ATT&CK techniques: Transfer Data to Cloud Account (T1537)Required data: AWS Audit LogDetector tags: Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Configuration, Data Detection & ResponseAttacker's goals: Exfiltrate sensitive data that resides on the snapshot.Investigative actions: Check if the identity intended to modify the snapshot. Check if the identity performed additional malicious operations within the cloud environment.Variations
Cloud snapshot of a database or storage instance was shared public
Low overridden
A cloud identity has shared a snapshot of an AWS database or storage instance. overridden
Cloud snapshot of a database or storage instance was shared with an unknown AWS account
Low overridden
A cloud identity has shared a snapshot of an AWS database or storage instance. overridden