Transfer Data to Cloud Account T1537
Tactic: Exfiltration
Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Events covered
1 catalog event is tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Security-Auditing | Event ID 5145 | A network share object was checked to see whether client can be granted desired access. |
Authoring guide
These 56 rules share fields, values, and exclusions.
Fields filtered most (76 distinct)
These fields appear most often in rule filters.
Top indicator values (192 distinct)
These values appear most often in rule predicates.
Exclusions (15 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 7 rules
- AWS EC2 VM Export Failure
- AWS S3 Data Management Tampering
- AWS Snapshot Backup Exfiltration
- Data Exfiltration to Unsanctioned Apps
- Github Fork Private Repositories Setting Enabled/Cleared
- Github Repository/Organization Transferred
- macOS Cloud Storage Access Tools
Elastic 14 rules
- AWS EC2 AMI Shared with Another Account
- AWS EC2 EBS Snapshot Shared or Made Public
- AWS EC2 Export Task
- AWS EC2 Full Network Packet Capture Detected
- AWS ECR Repository or Registry Policy Granted Public Access
- AWS RDS DB Snapshot Shared with Another Account
- AWS S3 Bucket Policy Added to Allow Public Access
- AWS S3 Bucket Policy Added to Share with External Account
- AWS S3 Bucket Replicated to Another Account
- Azure Blob Storage Container Access Level Modified
- GCP Logging Sink Modification
- Google Workspace Drive Data Transfer or Takeout Export Initiated
- M365 Exchange Mail Flow Transport Rule Created
- M365 Exchange Mail Flow Transport Rule Modified
Splunk 7 rules
- ASL AWS EC2 Snapshot Shared Externally
- AWS AMI Attribute Modification for Exfiltration
- AWS EC2 Snapshot Shared Externally
- AWS Exfiltration via Bucket Replication
- AWS Exfiltration via EC2 Snapshot
- AWS S3 Exfiltration Behavior Identified
- High Frequency Copy Of Files In Network Share
Kusto 8 rules
- AWSCloudTrail - RDS instance publicly exposed
- AWSCloudTrail - S3 bucket access point publicly exposed
- AWSCloudTrail - S3 bucket exposed via ACL
- AWSCloudTrail - S3 bucket exposed via policy
- AWSCloudTrail - S3 object publicly exposed
- Box - Item shared to external entity
- Dataverse - SharePoint document management site added or updated
- Power Platform - Connector added to a sensitive environment
YARA-L 4 rules
- AWS EC2 AMI Or Snapshot Shared Publicly
- AWS RDS Snapshot Shared Publicly
- GCP GCE Image Open To Public
- GitHub Outgoing Organization Transfer Initiated
Panther 16 rules
- Amazon Machine Image (AMI) Modified to Allow Public Access
- AppOmni Alert Passthrough
- AWS AMI Sharing
- AWS RDS Manual/Public Snapshot Created
- AWS RDS Snapshot Copied Cross-Region
- AWS RDS Snapshot Exported to S3
- AWS RDS Snapshot Shared
- AWS Resource Made Public
- AWS S3 Large Download
- AWS S3 Object Copied to External Account Bucket
- AWS S3 Object Exfiltration WITH Object Deletion
- AWS Snapshot Made Public
- Databricks Data Movement with Explicit Credentials
- GCP GCS Bulk Object Rewrite Operation
- GCP GCS Object Copied to Different Bucket
- Snowflake External Data Share