Analytics BIOC Informational

AWS Transfer Family server created

A cloud identity created server using AWS Transfer Family service.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Data Detection & Response
Attacker's goals:

Attacker is trying to exfiltrate data out of AWS storage services.

Investigative actions:

Check if the AWS Transfer Family service is used by your organization. Check if {identity_name} created a server using this service before. Check which storage instances were affected by {transfer_server_id} server.

Test period:
N/A (single event)
Deduplication:
5 Days
1 variation:
  • Unusual cloud transfer service activity Low (parent: Informational)