Data Movement
Atlas home · Research path · Operational families · Anomaly models · Visual index
Consolidated 27 September 2026 from the revised publication. Source-reported incidents, proposed models, functional tests, and synthetic results remain separate evidence classes. Provenance and review scope.
Unexpected access, export, copy or synchronization involving a source and destination.
Telemetry contract: Application/storage audit, destination account, object sensitivity and transfer counters where available.
Candidate method [unvalidated until tested]: Keep event counts, distinct objects, bytes and records separate; evaluate destination and authorization context.
Benign alternatives and limits: Approved export, backup, migration and collaboration can resemble exfiltration.

Text equivalent and full-size diagram
Approved migration and backup can resemble exfiltration.
Customer records are the defined source. An export or sync job, linked to an actor and session, transfers them to a new storage account whose ownership needs review.
The synthetic service identity uses a destination outside its previous workflow. Check whether that destination is approved for this data and verify who controls it.
Keep audit-event counts, distinct objects, rows or records, and bytes separate. Match source, actor, job and destination; backups, migrations and collaboration can explain the transfer.
Evidence tags: Cloud and SaaS · Identity and access. Statistical forms: contextual, collective.
Browse articles and guides: Data Movement.
Reported incidents and detection interpretations
UNC5537 and Snowflake customer data theft
Period: 2024. Evidence: campaign reported by the cited source.
Observed [source-reported]: The campaign moved stolen database content out of customer environments and used external hosting or storage infrastructure. Mandiant: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion.
Anomaly interpretation [inferred]: Compare source data, export operation and destination ownership with normal business flows. An authorized account can execute an unauthorized transfer.
Telemetry to validate: Database queries, export commands, storage destinations and identity-to-session correlation.
Boundary / competing explanation: A dataset's sensitivity and the destination's authorization must come from customer context, not its public hostname alone.
ATT&CK [author-mapped behavior, not actor attribution]: T1078.004 — Valid Accounts: Cloud Accounts
UNC3944 help-desk compromise and SaaS data theft
Period: 2023–2024 investigations reported June 2024. Evidence: campaign reported by the cited source.
Observed [source-reported]: Mandiant obtained victim Airbyte logs and described Airbyte/Fivetran transfers from SaaS data sources to attacker-owned storage. Mandiant: UNC3944 Targets SaaS Applications.
Anomaly interpretation [inferred]: Join connector creation and authorization to source objects, destination account ownership and transfer activity, even when the transport is normal cloud traffic.
Telemetry to validate: Connector job logs, SaaS audit, consent records and cloud-storage access history.
Boundary / competing explanation: A legitimate sync product is not an IOC. Visibility depends on where the connector runs and which logs are collected.
ATT&CK [author-mapped behavior, not actor attribution]: T1567.002 — Exfiltration Over Web Service: Exfiltration to Cloud Storage
Crosslinks: Volumetric · Peer-Group. Statistical foundation in the Anomaly Detection Atlas. Related research: Detecting Malicious Insider Activity: A Technical Detection Engineering Guide.
Illustrative scenarios (not additional incidents):
-
A user who usually views a few HR documents per week suddenly exports entire employee folders to a ZIP archive and syncs them to a personal cloud storage destination.
-
A service account that normally reads small sets of objects begins copying thousands of customer records from one S3 bucket to an external account.
-
A SaaS user who typically works inside dashboards suddenly performs multiple CSV exports of high-value reports in one session.
-
A workstation that normally accesses Office files locally starts reading large numbers of engineering documents and copying them to a removable device or network share.
-
A cloud admin account that usually performs management actions begins bulk snapshot export or cross-region object replication involving sensitive data classes.
Apply this analytical view
These are curated conceptual links, not claims that a specific model detected the cited incidents.
Models: Files, records, messages, or objects accessed in bulk · Email content collected · Data staged, compressed, or archived · Large outbound transfer · Data uploaded to cloud or web service · Transfers deliberately limited to evade controls.
Collection references: Cloud Storage Access · File Access · Network Traffic Flow. These describe data components, not equivalent connectors or guaranteed fields.
Technique workspaces
Follow the exact technique ID to source rules, associated tools, collection references, and documented lab candidates. A navigation association is not live validation.