AWS CloudTrail EC2 CreateInstanceExportTask Failure

Flags failed EC2 VM export task creation events in AWS CloudTrail to surface potential instance data extraction attempts.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Diogo Braz (SigmaHQ), DRL 1.1
Published
2020-04-16
Updated
2026-07-31

ATT&CK techniques

Collection → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Impact

What it detects

This rule identifies CloudTrail events where an EC2 VM export task is created (CreateInstanceExportTask) and the event indicates a failure. Attackers may attempt VM export to collect or exfiltrate information from an EC2 instance, and repeated or failed export attempts can still signal reconnaissance or data collection activity. The detection relies on CloudTrail telemetry fields for event name, event source, and response content indicating failure.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
AWS CloudTrail EC2 CreateInstanceExportTask Failure
Pivot detection · T1005 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.