Detection rules › Sigma

AWS Snapshot Backup Exfiltration

Status
test
Severity
medium
Log source
product aws, service cloudtrail
Author
Darin Smith
Source
github.com/SigmaHQ/sigma

Detects the modification of an EC2 snapshot's permissions to enable access from another account

MITRE ATT&CK coverage

TacticTechniques
ExfiltrationT1537 Transfer Data to Cloud Account

Event coverage

Rule body yaml

title: AWS Snapshot Backup Exfiltration
id: abae8fec-57bd-4f87-aff6-6e3db989843d
status: test
description: Detects the modification of an EC2 snapshot's permissions to enable access from another account
references:
    - https://www.justice.gov/file/1080281/download
author: Darin Smith
date: 2021-05-17
modified: 2021-08-19
tags:
    - attack.exfiltration
    - attack.t1537
logsource:
    product: aws
    service: cloudtrail
detection:
    selection_source:
        eventSource: ec2.amazonaws.com
        eventName: ModifySnapshotAttribute
    condition: selection_source
falsepositives:
    - Valid change to a snapshot's permissions
level: medium

Stages and Predicates

Stage 0: condition

selection_source

Stage 1: selection_source

selection_source:
    eventSource: ec2.amazonaws.com
    eventName: ModifySnapshotAttribute

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
eventNameeq
  • ModifySnapshotAttribute
eventSourceeq
  • ec2.amazonaws.com