Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0573 — Cross-Platform Detection of Data Transfer to Cloud Account
DET0573

Cross-Platform Detection of Data Transfer to Cloud Account

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1580 Analytic 1580
IaaS

Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.

AWS:CloudTrail ModifySnapshotAttribute AWS:CloudTrail PutBucketPolicy AWS:CloudTrail CreateSnapshot AWS:CloudTrail CopySnapshot AWS:VPCFlowLogs High volume internal-to-internal IP transfer or cross-account cloud transfer
[CrossAccountIDList] List of external cloud accounts authorized for snapshot or bucket sharing
[Region] Geographic region in which the sharing occurs (may impact logging availability)
[VolumeSizeThresholdGB] Threshold to alert on snapshot size or object volume
[TimeWindow] Temporal window between snapshot creation and external sharing
AN1581 Analytic 1581
Office Suite

Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.

m365:unified SharingSet m365:unified AnonymousLinkCreated m365:unified FileAccessed
[ExternalDomainList] Known partner or adversarial cloud identities/domains
[TimeWindow] Duration between file access and external sharing
[SharingMethod] Type of link (anonymous, internal, organization-wide) to alert on
AN1582 Analytic 1582
SaaS

Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.

saas:googledrive drive.permission.add saas:box collaboration.invite
[UserContext] Whether the user is in a high-privileged or VIP group
[DomainReputationList] Allowlist or blocklist of external SaaS domains
[PayloadVolumeThreshold] Size or number of shared files triggering alert

Detected Techniques

1

Details

MITRE ID
DET0573
STIX ID
x-mitre-detection-strategy--22a31282-d190-449b-a102-2d562f906b7d
Analytics
3
Techniques Detected
1
By Tactic
Exfiltration
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.