Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0009 ✕

Download CSV Show ATT&CK heatmap
  • EBS snapshots were created from an EC2 instance Informational Cloud 2 variations

    One or more EBS snapshots were created from an EC2 instance.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Data from Cloud Storage (T1530)
    Required data: AWS Audit Log
    Attacker's goals: Clone existing compute volumes for exfiltration purposes. This action may be a preliminary action before downloading snapshot blocks or creating volumes from the snapshots.
    Investigative actions: Confirm that the identity intended to create the described snapshots. Monitor the source instance for additional suspicious activities. Follow further actions done by the identity.

    Variations

    EBS snapshots were created from an EC2 instance attached one or more volumes with sensitive data

    Low overridden

    One or more EBS snapshots were created from an EC2 instance. The instance has one or more volumes attached containing sensitive data. overridden

    An unusual creation of EBS snapshots from an EC2 instances

    Low overridden

    One or more EBS snapshots were created from an EC2 instance. The operation was not performed by this identity in the last 30 days. overridden