Analytics BIOC Informational

Cloud snapshot created or modified

A cloud identity has created or modified a cloud snapshot.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Exfiltration (TA0010) Defense Evasion (TA0005) Collection (TA0009)
ATT&CK techniques: Transfer Data to Cloud Account (T1537) Modify Cloud Compute Infrastructure (T1578) Data from Cloud Storage (T1530)
Detector tags: Cloud Data Asset Disaster Recovery Risks Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:

Exfiltrate sensitive data that resides on the snapshot.

Investigative actions:

Check if the identity intended to create or modify the snapshot. Check if the identity performed additional malicious operations within the cloud environment.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Cloud snapshot was configured for public access Low (parent: Informational)
  • Cloud snapshot was shared with an unusual AWS account(s) Low (parent: Informational)
  • Previously unseen GCP principal was bound to cloud snapshot Low (parent: Informational)