Analytics BIOC
Informational
✕
Cloud snapshot created or modified
A cloud identity has created or modified a cloud snapshot.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Exfiltration (TA0010) Defense Evasion (TA0005) Collection (TA0009)
ATT&CK techniques: Transfer Data to Cloud Account (T1537) Modify Cloud Compute Infrastructure (T1578) Data from Cloud Storage (T1530)
Detector tags: Cloud Data Asset Disaster Recovery Risks Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:
Exfiltrate sensitive data that resides on the snapshot.
Investigative actions:
Check if the identity intended to create or modify the snapshot. Check if the identity performed additional malicious operations within the cloud environment.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Cloud snapshot was configured for public access Low (parent: Informational)
- Cloud snapshot was shared with an unusual AWS account(s) Low (parent: Informational)
- Previously unseen GCP principal was bound to cloud snapshot Low (parent: Informational)