1200KM / detection
T1537 Transfer Data to Cloud Account — Detection Rules
Detection workspace for T1537 Transfer Data to Cloud Account: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Github Fork Private Repositories Setting Enabled/Cleared · test · medium · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- Github Repository/Organization Transferred · test · medium · {"product":"github","service":"audit","definition":"Requirements: The audit log streaming feature must be enabled to be able to receive such logs. You can enable following the documentation here: https://docs.github.com/en/enterprise-cloud@latest/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/streaming-the-audit-log-for-your-enterprise#setting-up-audit-log-streaming"}
- AWS EC2 VM Export Failure · test · low · {"product":"aws","service":"cloudtrail"}
- AWS S3 Data Management Tampering · test · low · {"product":"aws","service":"cloudtrail"}
- AWS Snapshot Backup Exfiltration · test · medium · {"product":"aws","service":"cloudtrail"}
- Data Exfiltration to Unsanctioned Apps · test · medium · {"service":"threat_management","product":"m365"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0573 Cross-Platform Detection of Data Transfer to Cloud Account
AN1580 Analytic 1580
Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.
AN1581 Analytic 1581
Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.
AN1582 Analytic 1582
Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Cloud Storage Metadata · DC0027
- Cloud Storage Modification · DC0023
- Network Traffic Content · DC0085
- Snapshot Creation · DC0057
- Snapshot Metadata · DC0062
- Snapshot Modification · DC0058
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.