kevmap

TechniquesT1074.002 › AN0198

AN0198 Analytic 0198

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts.</p>
Detects
T1074.002 Remote Data Staging
Part of
DET0071 Detection of Remote Data Staging Prior to Exfiltration

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailGetObject, CopyObjectDC0025 Cloud Storage Access
AWS:VPCFlowLogsTraffic between instancesDC0085 Network Traffic Content
esxi:hostdprocess execution across cloud VMDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
BucketNamePatternsDestination naming convention used for staging (e.g., temp-store)
IAMContextIAM role or user performing multi-host write ops
TransferWindowBurst of high-volume inter-VM transfers indicating staging