{"id":"T1578.001","name":"Create Snapshot","url":"https://attack.mitre.org/techniques/T1578/001","tactics":["defense-impairment"],"platforms":["IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0423","stix_id":"x-mitre-detection-strategy--160f132d-626e-412a-ae16-df265670c196","name":"Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot","url":"https://attack.mitre.org/detectionstrategies/DET0423","analytics":[{"id":"AN1187","stix_id":"x-mitre-analytic--05af7b9b-ec1a-4d6c-a944-64a7ad0eb2f5","name":"Analytic 1187","description":"Detection focuses on correlating snapshot creation events with subsequent instance creation and mounting activities. From a defender perspective, suspicious sequences include snapshot creation by unexpected or newly created IAM users, snapshots created from sensitive volumes without preceding change-control activity, or snapshots immediately followed by mounting to unauthorized instances. Cross-referencing with user behavior, IP geolocation, and automation context helps distinguish benign backup operations from adversary-driven snapshot exploitation.","url":"https://attack.mitre.org/detectionstrategies/DET0423#AN1187","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"CreateSnapshot","data_component":"DC0057","data_component_name":"Snapshot Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"DescribeSnapshots","data_component":"DC0062","data_component_name":"Snapshot Metadata","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"UserContext","description":"IAM user, service account, or role performing snapshot creation. Tuned to allowlist known backup automation services."},{"field":"TimeWindow","description":"Frequency of snapshot creation in a defined period. Adjusted for environments with frequent automated backups."},{"field":"GeoLocation","description":"Unusual regions or IPs from which snapshot creation API calls originate. Helps identify cross-region snapshot abuse."},{"field":"VolumeSensitivity","description":"Tagging or classification of volumes being snapshotted. Tuned to prioritize alerts when sensitive volumes are copied."}],"live":true,"detection_strategies":["DET0423"],"techniques":["T1578.001"]}],"live":true,"version":"1.0","techniques":["T1578.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}