Skip to main content

Data Movement

Atlas home · Research path · Operational families · Anomaly models · Visual index

Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.

Unexpected access, export, copy or synchronization involving a source and destination.

Telemetry contract: Application/storage audit, destination account, object sensitivity and transfer counters where available.

Candidate method [unvalidated until tested]: Keep event counts, distinct objects, bytes and records separate; evaluate destination and authorization context.

Benign alternatives and limits: Approved export, backup, migration and collaboration can resemble exfiltration.

Data movement anomaly. Synthetic transfer of customer records through an export or sync job to a new storage account. Destination ownership and approval are unresolved; a changed route is an investigation lead, not confirmed exfiltration. Audit events, distinct objects, records and bytes are different measurements. Approved migration and backup can resemble exfiltration.
Figure 17. Data movement anomaly. Synthetic transfer of customer records through an export or sync job to a new storage account. Destination ownership and approval are unresolved; a changed route is an investigation lead, not confirmed exfiltration. Audit events, distinct objects, records and bytes are different measurements.SYNTHETIC ILLUSTRATION · USER-SUPPLIEDSources: NIST SP 800-94.
Text equivalent and full-size diagram

Approved migration and backup can resemble exfiltration.

Customer records are the defined source. An export or sync job, linked to an actor and session, transfers them to a new storage account whose ownership needs review.

The synthetic service identity uses a destination outside its previous workflow. Check whether that destination is approved for this data and verify who controls it.

Keep audit-event counts, distinct objects, rows or records, and bytes separate. Match source, actor, job and destination; backups, migrations and collaboration can explain the transfer.

Open original full-size asset

Evidence tags: Cloud and SaaS · Identity and access. Statistical forms: contextual, collective.

Browse articles and guides: Data Movement.

Reported incidents and detection interpretations

UNC5537 and Snowflake customer data theft​

Period: 2024. Evidence: campaign reported by the cited source.

Observed [source-reported]: The campaign moved stolen database content out of customer environments and used external hosting or storage infrastructure. Mandiant: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion.

Anomaly interpretation [inferred]: Compare source data, export operation and destination ownership with normal business flows. An authorized account can execute an unauthorized transfer.

Telemetry to validate: Database queries, export commands, storage destinations and identity-to-session correlation.

Boundary / competing explanation: A dataset's sensitivity and the destination's authorization must come from customer context, not its public hostname alone.

ATT&CK [author-mapped behavior, not actor attribution]: T1078.004 — Valid Accounts: Cloud Accounts

UNC3944 help-desk compromise and SaaS data theft​

Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.

Observed [source-reported]: Mandiant obtained victim Airbyte logs and described Airbyte/Fivetran transfers from SaaS data sources to attacker-owned storage. Mandiant: UNC3944 Targets SaaS Applications.

Anomaly interpretation [inferred]: Join connector creation and authorization to source objects, destination account ownership and transfer activity, even when the transport is normal cloud traffic.

Telemetry to validate: Connector job logs, SaaS audit, consent records and cloud-storage access history.

Boundary / competing explanation: A legitimate sync product is not an IOC. Visibility depends on where the connector runs and which logs are collected.

ATT&CK [author-mapped behavior, not actor attribution]: T1567.002 — Exfiltration Over Web Service: Exfiltration to Cloud Storage

Crosslinks: Volumetric · Peer-Group. Statistical foundation in the Anomaly Detection Atlas. Related research: Detecting Malicious Insider Activity: A Technical Detection Engineering Guide.

Illustrative scenarios (not additional incidents):

  • A user who usually views a few HR documents per week suddenly exports entire employee folders to a ZIP archive and syncs them to a personal cloud storage destination.

  • A service account that normally reads small sets of objects begins copying thousands of customer records from one S3 bucket to an external account.

  • A SaaS user who typically works inside dashboards suddenly performs multiple CSV exports of high-value reports in one session.

  • A workstation that normally accesses Office files locally starts reading large numbers of engineering documents and copying them to a removable device or network share.

  • A cloud admin account that usually performs management actions begins bulk snapshot export or cross-region object replication involving sensitive data classes.

Apply this analytical view​

These are curated conceptual links, not claims that a specific model detected the cited incidents.

Models: Files, records, messages, or objects accessed in bulk · Email content collected · Data staged, compressed, or archived · Large outbound transfer · Data uploaded to cloud or web service · Transfers deliberately limited to evade controls.

Collection references: Cloud Storage Access · File Access · Network Traffic Flow. These describe data components, not equivalent connectors or guaranteed fields.

Technique workspaces​

Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.