Analytics Informational

AWS EBS enumeration activity

EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Infrastructure Discovery (T1580) Cloud Service Discovery (T1526)
Attacker's goals:

Identify existing EBS volumes and snapshots to understand what storage resources are available and in use. Assess if snapshots are shared with other accounts or publicly accessible. Identify potential data exfiltration paths or targets.

Investigative actions:

Review which EBS API calls were executed and their frequency. Analyze the identity performing the actions. Inspect sharing or access configurations of enumerated snapshots.

Test period:
1 Hour
Deduplication:
1 Day