Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0024 — Cloud Storage Creation
DC0024

Cloud Storage Creation

1 analytic(s) · 1 detection strategy(ies)

Description

Cloud Storage Creation refers to the initial creation of a new cloud storage resource, such as buckets, containers, or directories, within a cloud environment. This action is critical to track as it might indicate the legitimate provisioning of resources or unauthorized actions taken by adversaries to stage, store, or exfiltrate data. Examples: - AWS S3 Bucket Creation: An AWS user creates a new S3 bucket using the `CreateBucket` API call. - Azure Blob Storage Container Creation: A user creates a new container in Azure Blob Storage using the `Create Container` operation. - Google Cloud Storage Bucket Creation: A Google Cloud user creates a new bucket using `storage.buckets.create`. - OpenStack Swift Container Creation: A user creates a new container in OpenStack Swift using the `PUT` method.

Referenced in Analytics

1
AN0690 Analytic 0690 DET0247

Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region).

AWS:CloudTrail AWS:CloudTrail CloudTrail:GetCallerIdentity AWS:VPCFlowLogs

Details

MITRE ID
DC0024
STIX ID
x-mitre-data-component--59ec10d9-546b-4b8e-bccb-fa85f71e5055
Analytics
1
Detection Strategies
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.