Transfer Data to Cloud Account T1537
Tactic: Exfiltration
Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Security-Auditing | Event ID 5145 | A network share object was checked to see whether client can be granted desired access. |
Authoring guide
Patterns shared across the 55 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (76 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (187 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (15 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 7 rules
- AWS EC2 VM Export Failure
- AWS S3 Data Management Tampering
- AWS Snapshot Backup Exfiltration
- Data Exfiltration to Unsanctioned Apps
- Github Fork Private Repositories Setting Enabled/Cleared
- Github Repository/Organization Transferred
- macOS Cloud Storage Access Tools
Elastic 13 rules
- AWS EC2 AMI Shared with Another Account
- AWS EC2 EBS Snapshot Shared or Made Public
- AWS EC2 Export Task
- AWS EC2 Full Network Packet Capture Detected
- AWS RDS DB Snapshot Shared with Another Account
- AWS S3 Bucket Policy Added to Allow Public Access
- AWS S3 Bucket Policy Added to Share with External Account
- AWS S3 Bucket Replicated to Another Account
- Azure Blob Storage Container Access Level Modified
- GCP Logging Sink Modification
- Google Workspace Drive Data Transfer or Takeout Export Initiated
- M365 Exchange Mail Flow Transport Rule Created
- M365 Exchange Mail Flow Transport Rule Modified
Splunk 7 rules
- ASL AWS EC2 Snapshot Shared Externally
- AWS AMI Attribute Modification for Exfiltration
- AWS EC2 Snapshot Shared Externally
- AWS Exfiltration via Bucket Replication
- AWS Exfiltration via EC2 Snapshot
- AWS S3 Exfiltration Behavior Identified
- High Frequency Copy Of Files In Network Share
Kusto 8 rules
- AWSCloudTrail - RDS instance publicly exposed
- AWSCloudTrail - S3 bucket access point publicly exposed
- AWSCloudTrail - S3 bucket exposed via ACL
- AWSCloudTrail - S3 bucket exposed via policy
- AWSCloudTrail - S3 object publicly exposed
- Box - Item shared to external entity
- Dataverse - SharePoint document management site added or updated
- Power Platform - Connector added to a sensitive environment
YARA-L 4 rules
- AWS EC2 AMI Or Snapshot Shared Publicly
- AWS RDS Snapshot Shared Publicly
- GCP GCE Image Open To Public
- GitHub Outgoing Organization Transfer Initiated
Panther 16 rules
- Amazon Machine Image (AMI) Modified to Allow Public Access
- AppOmni Alert Passthrough
- AWS AMI Sharing
- AWS RDS Manual/Public Snapshot Created
- AWS RDS Snapshot Copied Cross-Region
- AWS RDS Snapshot Exported to S3
- AWS RDS Snapshot Shared
- AWS Resource Made Public
- AWS S3 Large Download
- AWS S3 Object Copied to External Account Bucket
- AWS S3 Object Exfiltration FOLLOWED BY Object Deletion
- AWS Snapshot Made Public
- Databricks Data Movement with Explicit Credentials
- GCP GCS Bulk Object Rewrite Operation
- GCP GCS Object Copied to Different Bucket
- Snowflake External Data Share