kevmap

TechniquesT1074 › AN0043

AN0043 Analytic 0043

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances.</p>
Detects
T1074 Data Staged
Part of
DET0014 Detection of Data Staging Prior to Exfiltration

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailGetObject, CopyObjectDC0025 Cloud Storage Access
gcp:auditWrite operations to storageDC0055 File Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
CloudBucketListStaging bucket or mount point for data
InstanceTagBehavior restricted to specific ephemeral instances
ObjectWriteThresholdVolume or size of files pushed in burst