MITRE ATT&CK technique
Transfer Data to Cloud Account detection rulesT1537
Transfer Data to Cloud Account (T1537) is a MITRE ATT&CK technique in the Exfiltration tactic. This page lists the 6 community-maintained Sigma detection rules in the library mapped to T1537 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target aws, github, m365.
Tactic
AWS Snapshot Backup Exfiltration
mediumDetects the modification of an EC2 snapshot's permissions to enable access from another account
aws
Data Exfiltration to Unsanctioned Apps
mediumDetects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
m365
Github Fork Private Repositories Setting Enabled/Cleared
mediumDetects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
github
Github Repository/Organization Transferred
mediumDetects when a repository or an organization is being transferred to another location.
github
AWS EC2 VM Export Failure
lowAn attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
aws
AWS S3 Data Management Tampering
lowDetects when a user tampers with S3 data management in Amazon Web Services.
aws