Suspicious EBS Snapshot Shared With External Account via CloudTrail

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-08-04
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Impact

What it detects

This rule detects ModifySnapshotAttribute events that add CREATE_VOLUME_PERMISSION for a specific external AWS account, sharing an EBS snapshot outside the owner account. Adversaries share a snapshot they created with an attacker-controlled account so they can restore the volume elsewhere and exfiltrate its data. Externally sharing a snapshot bypasses direct data reads and is a known cloud exfiltration technique.

Related detections9 linkedT1537 — drag to rearrange
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
AWS CloudTrail EC2 CreateInstanceExportTask Failure
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Pivot detection · T1537 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.