Elastic medium stable kql
AWS EC2 Export Task
Identifies successful export tasks of EC2 instances via the APIs CreateInstanceExportTask, ExportImage, or CreateStoreImageTask. These exports can be used by administrators for legitimate VM migration or backup workflows however, an attacker with access to an EC2 instance or AWS credentials can export a VM or its image and then transfer it off-account for exfiltration of data.
Detection Logic
data_stream.dataset: "aws.cloudtrail" and
event.provider: "ec2.amazonaws.com" and
event.action: ("CreateInstanceExportTask" or "ExportImage" or "CreateStoreImageTask") and
event.outcome: "success" False Positives
- ⚠ VM export and EC2 image creation may be done by system administrators, DevOps or migration teams as part of planned maintenance, disaster-recovery or known backup methods. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Exports from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Field Validations
Loading…
Comments (0)
Loading comments...