Analytics BIOC Informational

Cloud compute volume creation attempt

An attempt was made to create an EBS volume.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Defense Evasion (TA0005) Collection (TA0009)
ATT&CK techniques: Modify Cloud Compute Infrastructure (T1578) Data from Cloud Storage (T1530)
Attacker's goals:

Exfiltrate sensitive data stored on snapshots.

Investigative actions:

Review recent activity related to the identity, the created volume and the cloud snapshot.

Test period:
N/A (single event)
Deduplication:
5 Days
1 variation:
  • Cloud compute volume creation attempt using Cloud Formation or Terraform Informational