Suspicious EC2 Snapshot Attribute Modification for External Sharing via CloudTrail

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects the ModifySnapshotAttribute CloudTrail event which attackers use to share an EBS snapshot with an external AWS account for data exfiltration as highlighted in this Elastic analysis. Sharing snapshots outside the organization is a low volume administrative action that when unexpected indicates exfiltration of volume data.

Related detections9 linkedT1537 — drag to rearrange
Suspicious Cross-Project Compute Snapshot Creation via GCP Audit
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
Suspicious EC2 Snapshot Attribute Modification for External Sharing via CloudTrail
Pivot detection · T1537 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.