Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0023 — Cloud Storage Modification
DC0023

Cloud Storage Modification

5 analytic(s) · 3 detection strategy(ies)

Description

Cloud Storage Modification involves tracking changes made to cloud storage infrastructure, including updates to settings, permissions, or stored data. Examples include modifying object access control lists (ACLs), uploading new objects, or updating bucket policies. Examples: AWS S3: An object is uploaded or its ACL is modified. - Azure Blob Storage: A blob's metadata or permissions are updated. - Google Cloud Storage: An object's lifecycle policy is updated, or a bucket policy is changed. - OpenStack Swift: Modifications to container settings or uploading of new objects.

Referenced in Analytics

5
AN0117 Analytic 0117 DET0041

Adversary with write access to storage modifies lifecycle policies (e.g., via PutBucketLifecycle) to schedule rapid object deletion across one or more storage buckets. This is often used to trigger impact (destruction), remove logs (defense evasion), or force extortion (ransomware).

AWS:CloudTrail
AN0606 Analytic 0606 DET0215

Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.

AWS:CloudTrail
AN1580 Analytic 1580 DET0573

Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.

AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:VPCFlowLogs
AN1581 Analytic 1581 DET0573

Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.

m365:unified m365:unified m365:unified
AN1582 Analytic 1582 DET0573

Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.

saas:googledrive saas:box

Details

MITRE ID
DC0023
STIX ID
x-mitre-data-component--45977f14-1bcc-4ec4-ac14-a30fd3a11f44
Analytics
5
Detection Strategies
3
Leaving Threaticon

This link opens an external site that isn't part of the platform.