Modify Cloud Compute Infrastructure: Create Snapshot T1578.001

Tactic: Defense Impairment

An adversary may create a snapshot or data backup within a cloud account to evade defenses. A snapshot is a point-in-time copy of an existing cloud compute component such as a virtual machine (VM), virtual hard drive, or volume. An adversary may leverage permissions to create a snapshot in order to bypass restrictions that prevent access to existing compute service infrastructure, unlike in Revert Cloud Instance where an adversary may revert to a snapshot to evade detection and remove evidence of their presence.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (4 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1in 1createdbclustersnapshot, createdbsnapshot
Provider_Name1eq 1rds.amazonaws.com
event.dataset1eq 1aws.cloudtrail
event.outcome1eq 1success

Top indicator values (5 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
createdbclustersnapshot
1
EventTypein
createdbsnapshot
1
Provider_Nameeq
rds.amazonaws.com
19
event.dataseteq
aws.cloudtrail
117
event.outcomeeq
success
1375

Exclusions (2 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
aws::userAgentcontains
pulumi
1
aws::userAgentcontains
terraform
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: AWS

Domain: Cloud

Elastic 1 rule