Analytics BIOC
Informational
✕
EBS volume attachment attempt
An attempt was made to attach an EBS volume to an EC2 instance.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Modify Cloud Compute Infrastructure (T1578)
Attacker's goals:
Attach a volume to a cloud instance to exfiltrate sensitive data stored on EBS volumes.
Investigative actions:
Review recent activity related to the identity, the attached volume and the cloud instance.
- Test period:
- N/A (single event)
- Deduplication:
- 5 Days
2 variations:
- EBS volume attachment attempt for volume with sensitive data Low (parent: Informational)
- EBS volume attachment attempt using Cloud Formation or Terraform Informational