Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0423 — Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot
DET0423

Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1187 Analytic 1187
IaaS

Detection focuses on correlating snapshot creation events with subsequent instance creation and mounting activities. From a defender perspective, suspicious sequences include snapshot creation by unexpected or newly created IAM users, snapshots created from sensitive volumes without preceding change-control activity, or snapshots immediately followed by mounting to unauthorized instances. Cross-referencing with user behavior, IP geolocation, and automation context helps distinguish benign backup operations from adversary-driven snapshot exploitation.

AWS:CloudTrail CreateSnapshot AWS:CloudTrail DescribeSnapshots
[UserContext] IAM user, service account, or role performing snapshot creation. Tuned to allowlist known backup automation services.
[TimeWindow] Frequency of snapshot creation in a defined period. Adjusted for environments with frequent automated backups.
[GeoLocation] Unusual regions or IPs from which snapshot creation API calls originate. Helps identify cross-region snapshot abuse.
[VolumeSensitivity] Tagging or classification of volumes being snapshotted. Tuned to prioritize alerts when sensitive volumes are copied.

Detected Techniques

1

Defense Impairment (1)

Details

MITRE ID
DET0423
STIX ID
x-mitre-detection-strategy--160f132d-626e-412a-ae16-df265670c196
Analytics
1
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.